IPsec configuration examples: Difference between revisions
no edit summary
No edit summary |
No edit summary |
||
Line 43: | Line 43: | ||
* Login to the router's WebUI and go to '''Services → VPN → IPsec'''. Enter a custom name (for this example we use ''RUT1'') for the IPsec instance click the "Add" button: | * Login to the router's WebUI and go to '''Services → VPN → IPsec'''. Enter a custom name (for this example we use ''RUT1'') for the IPsec instance click the "Add" button: | ||
[[File: | [[File:Ipsec1.png|alt=|1126x1126px]] | ||
---- | ---- | ||
* Click the "Edit" button located next to the newly created instance: | * Click the "Edit" button located next to the newly created instance: | ||
[[File: | [[File:Ipsec2.png|alt=|1129x1129px]] | ||
---- | ---- | ||
* You will be redirected to the instance's configuration window. From here we will discuss how to configure both instances (''RUT1'' and ''RUT2''). Creating a second instance is analogous to how we created the first one - just login to the second router and repeat the first two steps. Although not mandatory, we recommend that you use a distinct name for the second instance (for this example we use ''RUT2'') for easier management purposes. <br> The specifics of both configurations are described in the figure below: | * You will be redirected to the instance's configuration window. From here we will discuss how to configure both instances (''RUT1'' and ''RUT2''). Creating a second instance is analogous to how we created the first one - just login to the second router and repeat the first two steps. Although not mandatory, we recommend that you use a distinct name for the second instance (for this example we use ''RUT2'') for easier management purposes. <br> The specifics of both configurations are described in the figure below: | ||
[[File: | [[File:Ipsec3.png|alt=|1150x1150px]] | ||
* Below are explanations of the parameters highlighted in the figure above. Other parameters (not highlighted) are defaults. You can find descriptions for these parameters in the '''[[VPN#IPsec|VPN manual page, IPsec section]]''' | * Below are explanations of the parameters highlighted in the figure above. Other parameters (not highlighted) are defaults. You can find descriptions for these parameters in the '''[[VPN#IPsec|VPN manual page, IPsec section]]''' | ||
** '''Enable''' - enables the IPsec instance | **'''Enable''' - enables the IPsec instance | ||
** ''' | ** '''Remote Endpoint''' - the Public IP address of the opposite router, leaving empty will force IPSec to only accept connections. | ||
** '''Pre shared key''' - a shared password used for authentication between the peers. The value of this field must match on both instances | ** '''Pre shared key''' - a shared password used for authentication between the peers. The value of this field must match on both instances | ||
** ''' | **'''Local Identifier''' - private IP address of your router. | ||
** '''Remote | **'''Remote Identifier''' - private IP of the opposite router. | ||
** ''' | ** '''Local subnet''' - routers local subnet. | ||
** '''Remote subnet''' - opposite routers subnet. | |||
'''NOTE''': remember to replace certain parameter values (like IP addresses) with your own relevant data. | '''NOTE''': remember to replace certain parameter values (like IP addresses) with your own relevant data. | ||
---- | ---- | ||
* The last step in configuring the IPsec instances is ''' | * The last step in configuring the IPsec instances is '''Proposal settings'''. Make sure they match with the Phase settings ('''both Phase 1 and Phase 2''') of the incoming connection: | ||
[[File: | [[File:Ipsec4.png|alt=|1572x1572px]] | ||
When you're finished with the configuration, don't forget to click the "Save" button. | When you're finished with the configuration, don't forget to click the "Save" button. |