Local and Remote Identifier
Select Local Gateway
: If the device has more than one active WAN
interface, select the interface to be used for VPN. You must configure
this WAN interface’s IP address in VPN Tracker as the VPN Gateway.
Local Identity Type
: The local identity’s type on the device must
match the
Remote
Identifier Type (Basic > Identifiers) in VPN Tracker.
Local Identity Data:
The local identity data on the device must match
the
Remote
Identifier (Basic > Identifiers) in VPN Tracker.
Remote Host Configuration Record
: When Mode Config is used, select the appropriate Mode Config record here.
Remote Identity Type
: The type set on the device must match the
Local
Identifier Type (Basic > Identifiers) in VPN
Tracker.
Remote Identity Data:
The remote identity data on the device must match the
Local
Identifier (Basic > Identifiers) in VPN
Tracker.
IKE SA Parameters
Encryption Algorithm
: The encryption algorithm must match the encryption algorithm configured in VPN Tracker in
Advanced > Phase 1 > Encryption Algorithms. The device uses 3DES by default, which is generally a good choice.
AES-128/192/256 are considered to be even more secure (AES-192/AES-256 are only available in the Professional
Edition of VPN Tracker).
28
Note
For a VPN policy where the Traffic Selector is set to “
Any
” for the Remote IP, a
special Local Identifier
must be
used in VPN Tracker. It is constructed from the VPN policy name, a number between 1 and 10, and the Remote
Identity Data configured on the NETGEAR (refer to page 16 for an example).