D-Link DFL-1000 [71/168] Adding a remote gateway

D-Link DFL-1000 [71/168] Adding a remote gateway
DFL-1000 User Manual
71
Allow outbound
Select allow outbound.
Inbound NAT
Select inbound NAT if required.
Outbound NAT
Select outbound NAT if required.
Configuring IPSec redundancy
IPSec redundancy allows you to create a redundant AutoIKE key IPSec VPN configuration to two remote
VPN gateway addresses.
One use of IPSec redundancy is if you have configured your DFL-1000 with multiple internet connections
(see Configuring the DFL-1000 NPG for multiple Internet connections
)
For IPSec redundancy to work, both Internet connections must have static IP addresses.
To configure IPSec redundancy:
Add two remote gateways with the same settings (including the same authentication key) but with
different remote gateway addresses.
See Adding a remote gateway
.
Add two AutoIKE key tunnels with the same settings and add one of the remote gateways to each
tunnel.
See Adding an AutoIKE key VPN tunnel
.
Add two outgoing encrypt policies.
If you have multiple internet connections you can add an Int->Ext encrypt policy and an Int->DMZ
encrypt policy.
The source and destination of both policies must be the same. Add a different AutoIKE key tunnel to
each policy.
See Adding an encrypt policy
.
Adding a remote gateway
Add a remote gateway configuration to define the parameters that the DFL-1000 NPG uses to connect to
and establish an AutoIKE key VPN tunnel with a remote VPN gateway or a remote VPN client. The
remote gateway configuration consists of the IP address of the remote VPN gateway or client as well as
the P1 proposal settings required to establish the VPN tunnel. To successfully establish a VPN tunnel, the
remote VPN gateway or client must have the same authentication key and compatible P1 proposal
settings.
You can add one remote gateway and then create multiple AutoIKE key tunnels that include the same
remote gateway in their configurations. When the DFL-1000 NPG receives an IPSec VPN connection
request, it starts a remote gateway that matches the connection request. The VPN tunnel that starts
depends on the source and destination addresses of the IPSec VPN request, which the DFL-1000 NPG
matches with an encrypt policy.
To add a remote gateway:
Go to VPN > IPSEC > Remote Gateway .
Select New to add a new remote gateway.
Configure the remote gateway.

Содержание

Скачать