User's Manual

http://www.pepwave.com
61
Copyright @ 2012 Pepwave
11 IPsec VPN
Pepwave MAX IPsec VPN functionality securely connects one or more branch offices to your company's
main headquarters or to other branches. The data, voice, or video communications between these
locations are thus kept safe and confidential across the public Internet.
The IPsec VPN of the Pepwave MAX is especially designed for a multi-WAN environment. For instance, a
user sets up multiple IPsec profiles for his multi- WAN1 ~ WAN3 environment, if WAN1 is connected and
its health check turns up good, the IPsec traffic will go through this link. However, should unforeseen
problems (e.g. physically unplugged or ISP problems) arise and cause WAN1 to go down, our IPsec
implementation will make use of WAN2 and WAN3 accordingly, as failover purposes.
11.1 IPsec VPN Settings
All of our Pepwave products can make multiple IPsec VPN connections with Peplink, Pepwave as well as
Cisco or Juniper Routers.
Note that all LAN subnet and subnets behind it have to be unique. Otherwise, VPN members will not be
able to access each other.
All data can be routed over the VPN with a selection of encryption standards such as 3DES, AES-128
and AES-256.
To configure, navigate to Advanced > IPsec VPN:
A NAT-Traversal option and list of defined IPsec VPN profiles will be shown.
The NAT-Traversal option should be enabled if your system is behind a NAT router.
Click the New Connection button to create new IPsec VPN profiles that make
VPN connections to remote Peplink Balance, Pepwave MAX, Cisco or Juniper Routers via the available
WAN connections. To edit any of the profiles, click on its associated connection name in the leftmost
column.