Application Guide
15
NOTE: No matter on Main mode or Aggressive mode, once the client PC is behind a NAT 
device, we have to select FQDN as ID Type and the NAT device must support VPN 
passthrough, otherwise the VPN tunnel can’t be established.
Step 4:
Under IKE Proposal 1, we select 1 in this example. Enter Pre-shared Key and SA Lifetime you 
want, DPD is disabled.
Step 5:
Click on IPsec on the left menu, then IPsec Proposal. Select Security Protocol, ESP 
Authentication and ESP Encryption you want to enable on VPN tunnel. Here we 
use ESP, MD5 and 3DES for example.










