Operation Manual
Virtual Private Networking
113
N300 Wireless ADSL2+ Modem Router DGN2200v4
Add or Edit a VPN Auto Policy
An Auto VPN policy uses the IKE (Internet Key Protocol) to exchange and negotiate
parameters for the IPSec SA (security association). Because of this negotiation, not all of the
settings on this VPN gateway have to match the settings on the remote VPN endpoint.
Where settings have to match, this requirement is indicated.
To add an Auto policy:
1. Set the LAN IPs on each gateway to dif
ferent subnets and configure each correctly for
the Internet.
2. Select Advanced > Advanced - VPN > VPN Policies and click the Add Auto
Policy
button.
3. Specify the general settings:
• In the Policy Name field, enter a unique name.
This name is not supplied to the remote VPN endpoint. It is used only to help you
manage the policies.
• From the
Address Type list, select Fully Qualified Domain Name, Dynamic IP
Address or Fixed IP Address.
You can set up multiple remote dynamic IP policies, but only one policy can be
enabled at a time.
• If you want to ensure that a connection is kept open, or, if that is not possible, it is
quickly reestablished when disconnected, select the IKE Keep Alive check box and
fill in the Ping IP Address field.
• Fill in the Ping IP
Address field.
The ping IP address has to be associated with the remote endpoint. Either the WAN
or a LAN address can be used; a LAN address is preferable.
This IP address is
pinged to generate some traffic for the VPN tunnel.