Field
Description
NAT Traversal
NAT Traversal (NAT-T) also enables IPSec tunnels to be
opened via one or more devices on which network address
translation (NAT) is activated.
Without NAT-T, incompatibilities may arise between IPSec and
NAT (see RFC 3715, section 2). These primarily prevent the
setup of an IPSec tunnel from a host within a LANs and behind
a NAT device to another host or device. NAT-T enables these
kinds of tunnels without conflicts with NAT device, activated
NAT is automatically detected by the IPSec Daemon and NAT-T
is used.
The function is enabled with
#/
.
The function is enabled by default.
CA Certificates
Only for Phase-1 (IKE) Parameters
Only for Authentication Method =
1-0 -$
,
;-0
-$
or
;-0 %),
If you enable the Trust the following CA certificates option,
you can select up to three CA certificates that are accepted for
this profile.
This option can only be configured if certificates are loaded.
18.1.3 Phase-2 Profiles
You can define profiles for phase 2 of the tunnel setup just as for phase 1.
In the VPN->IPSec->Phase-2 Profiles menu, a list of all configured IPSec phase 2 profiles
is displayed.
Fig. 127:
VPN
->
IPSec
->
Phase-2 Profiles
In the Default column, you can mark the profile to be used as the default profile.
18 VPN
Funkwerk Enterprise Communications GmbH
332
bintec Rxxx2/RTxxx2