Chapter 13 VPN

Table 37 IPSec VPN: Add

LABEL

DESCRIPTION

NAT Traversal

Select this if any of these conditions are satisfied.

 

• This IKE SA might be used to negotiate IPSec SAs that use ESP as the active

 

protocol.

 

• There are one or more NAT routers between the LTE Device and remote IPSec

 

router, and these routers do not support IPSec pass-thru or a similar feature.

 

The remote IPSec router must also enable NAT traversal, and the NAT routers

 

have to forward packets with UDP port 500 and UDP 4500 headers unchanged.

 

 

Tunnel Name

Enter the name of the VPN connection.

 

 

Mode

Select the encapsulation mode. When net-netis selected, the connection will

 

operate in tunnel mode.

 

 

Local

 

 

 

Local Address

Select Single or Subnet to specify if the VPN connection begins at an IP address

Type

or subnet.

 

 

IP Address

If Single is selected, enter a (static) IP address on the LAN behind your LTE

Start

Device.

 

If Subnet is selected, specify IP addresses on a network by their subnet mask

 

by entering a (static) IP address on the LAN behind your LTE Device. Then enter

 

the subnet mask to identify the network address.

 

 

End/Subnet

If Subnet is selected, enter the subnet mask to identify the network address.

Mask

 

 

 

Remote

 

 

 

Remote

Select Single or Subnet to specify if the VPN connection terminates at an IP

Address Type

address or subnet.

 

 

IP Address

If Single is selected, enter a (static) IP address on the LAN behind the remote

Start

IPSec’s router.

 

If Subnet is selected, specify IP addresses on a network by their subnet mask

 

by entering a (static) IP address on the LAN behind the remote IPSec’s router.

 

Then enter the subnet mask to identify the network address.

 

 

End/Subnet

If Subnet is selected, enter the subnet mask to identify the network address.

Mask

 

 

 

Address Information

 

 

WAN Interface

Select the interface for the VPN gateway.

 

 

My IP Address

Enter the IP address of the LTE Device in the IKE SA.

 

 

Secure

Enter the IP address of the remote IPSec router in the IKE SA.

Gateway

 

Address

 

 

 

Local ID

Select IP to identify the LTE Device by its IP address.

 

Select DNS to identify this LTE Device by a domain name.

 

Select E-mailto identify this LTE Device by an e-mail address.

 

 

88

 

LTE6100 User’s Guide