Chapter 30 IPSec VPN
UAG5100 User’s Guide
290
• In a VPN gateway, the UAG and remote IPSec router can use certificates to authenticate each
other. Make sure the UAG and the remote IPSec router will trust each other’s certificates. See
.
30.2 The VPN Connection Screen
Click Configuration > VPN > IPSec VPN to open the VPN Connection screen. The VPN
Connection screen lists the VPN connection policies and their associated VPN gateway(s), and
various settings. In addition, it also lets you activate or deactivate and connect or disconnect each
VPN connection (each IPSec SA). Click a column’s heading cell to sort the table entries by that
column’s criteria. Click the heading cell again to reverse the sort order.
Figure 200
Configuration > VPN > IPSec VPN > VPN Connection
Each field is discussed in the following table. See
Table 131
Configuration > VPN > IPSec VPN > VPN Connection
LABEL
DESCRIPTION
Use Policy
Route to control
dynamic IPSec
rules
Select this to be able to use policy routes to manually specify the destination addresses of
dynamic IPSec rules. You must manually create these policy routes. The UAG automatically
obtains source and destination addresses for dynamic IPSec rules that do not match any of
the policy routes.
Clear this to have the UAG automatically obtain source and destination addresses for all
dynamic IPSec rules.
Ignore "Don't
Fragment"
setting in IP
header
Select this to fragment packets larger than the MTU (Maximum Transmission Unit) that have
the “don’t” fragment” bit in the IP header turned on. When you clear this the UAG drops
packets larger than the MTU that have the “don’t” fragment” bit in the header turned on.
Add
Click this to create a new entry.
Edit
Double-click an entry or select it and click Edit to open a screen where you can modify the
entry’s settings.
Remove
To remove an entry, select it and click Remove. The UAG confirms you want to remove it
before doing so.
Activate
To turn on an entry, select it and click Activate.
Inactivate
To turn off an entry, select it and click Inactivate.