User's Manual

16 IPsec VPN
IPsec VPN functionality securely connects one or more branch offices to your company's main
headquarters or to other branches. Data, voice, and video communications between these
locations are kept safe and confidential across the public Internet.
IPsec VPN on Pepwave routers is specially designed for multi-WAN environments. For
instance, if a user sets up multiple IPsec profiles for a multi-WAN environment and WAN1 is
connected and healthy, IPsec traffic will go through this link. However, should unforeseen
problems (e.g., unplugged cables or ISP problems) cause WAN1 to go down, our IPsec
implementation will make use of WAN2 and WAN3 for failover.
16.1 IPsec VPN Settings
Many Pepwave products can make multiple IPsec VPN connections with Peplink, Pepwave,
Cisco, and Juniper routers. Note that all LAN subnets and the subnets behind them must be
unique. Otherwise, VPN members will not be able to access each other. All data can be routed
over the VPN with a selection of encryption standards, such as 3DES, AES-128, and
AES-256. To configure IPsec VPN on Pepwave devices that support it, navigate to
Advanced>IPsec VPN.
A NAT-Traversal option and list of defined IPsec VPN profiles will be shown. NAT-Traversal
should be enabled if your system is behind a NAT router. Click the New Profile button to
create new IPsec VPN profiles that make VPN connections to remote Pepwave, Cisco, or
Juniper routers via available WAN connections. To edit any of the profiles, click on its
associated connection name in the leftmost column.