DPtech FW1000 Series Firewall Products User Configuration Guide
8-216
Item
Description
Advanced configuration
Select whether to enable the NAT traverse function
Select whether to enable the NAT session keepalive mechanism, configuring the
intervals for sending NAT session keepalive packets (default is 20 Sec)
Select whether to user IPsec acceleration
Select whether to enable the layer 2 IPSec
Select whether to enable UDP checksum
Select a mode for the route add mode ( This configuration takes effect after restart IPsec)
Table8-2 describes the configuration items of the IPSec VPN client access mode and gateway-gateway mode.
Table8-2
IPSec VPN client access mode and gateway-gateway mode
Item
Description
Connection
Name
Bind
Interface
Advanced Configuration
Displays the name of the IPSec rule.
Status
Display the status of the IPSec rule.
Local IP Address
Displays the local IP address for the IPSec rule.
Remote IP address
Displays the remote IP address for the IPSec rule.
Local Device ID
Auto:(The system auto-select the local IP address as the local device ID)
Host Name:(Required when NAT traverse is configured)
IP Address:(Manually input any IP address on the local device as the local ID)
Local Certificate ID Alias:(Required when it is required to strictly check the
validity of the remote certification ID alias)
Remote device ID
Auto:(The system auto-select the local IP address as the local device ID)
Host Name:(Required when NAT traverse is configured)
IP Address:(Manually input any IP address on the local device as the local ID)
Local Certificate ID Alias:(Required when it is required to strictly check the
validity of the remote certification ID alias)
Client ID
Configure the client ID number
Subnets Available to the clients
List The Encryption Protection Subnets To The Clients
Authentication Mode
There are four kinds of authentication method provided for you, including
Pre-shared key:
Digital Certificate: usercert.cer(Select the local certificate for certificate
authentication)
Xauth Authentication
Assign private IP address for clients