User's Manual

User Manual
http://www.pepwave.com
56
Copyright © 3/27/14 Pepwave
Enable
Select Yes to enable this SpeedFusion profile.
Name
Name representing this profile. The name can be any combination of
alphanumeric characters (0-9, A-Z, a-z), underscore (_), dash (-), and/or
non-leading/trailing spaces ( ).
Encryption
Select 256-bit AES to enable encryption or select Off to disable it.
Remote ID
Name representing the remote peer. The VPN profile will established only
if the remote unit’s ID or serial number matches Remote ID. This ensures
that connections are made only with authorized remote units. If a remote
unit is later replaced, Remote ID must be updated to match the unit’s ID
or serial number.
Authentication
Peer authentication method. Choose from By Remote ID only or
Preshared key.
Pre-shared Key
Optional field which defines the pre-shared key used for this particular
VPN connection. The VPN connection's session key will be further
protected by the factor of the pre-shared key. The connection will be up
only if the pre-shared keys on each side match. When the peer is running
firmware 5.0 or 5.1, this setting will be ignored.
Remote IP
Addresses / Host
Names
Enter Internet host names and/or the IP addresses of the remote unit in
this field. You may enter only one of the remote unit's WAN IP
addresses/host names here even if I the remote unit has multiple WAN
connections. Note that IP addresses/host names must be separated by a
space or a carriage return. When this field is filled, connection to the
remote unit will be attempted. If this field is left blank, the corresponding
field at the remote unit must be filled. When the state of any WAN
connection changes, the WAN IP addresses will be exchanged.
Layer 2 Bridging
When this check box is unchecked, traffic between local and remote
networks will be IP forwarded. To bridge the Ethernet network of an
Ethernet port on a local and remote network, select this check box. When
this check box is selected, the two networks will become a single LAN,
and any broadcast (e.g., ARP requests) or multicast traffic (e.g., Bonjour)
will be sent over the VPN.
Management VLAN
ID
This field specifies the VLAN ID with which the VPN's traffic should be
tagged before sending the traffic to the bridge port. If no VLAN tagging is
needed, select No VLAN. To define a new VLAN ID, click New... and
input the VLAN ID. VLAN IDs that are not referenced by any VPN profiles
will be removed from the list automatically. Default is No VLAN.