![](https://pdfstore-manualsonline.prod.a.ki/pdfasset/5/4d/54d9d5bd-2669-4c29-b57c-fe9ec46fb9ed/54d9d5bd-2669-4c29-b57c-fe9ec46fb9ed-bg20.png)
UsingtheRouter’sWebInterface 32
DefiningVirtualPrivateNetworks(VPNs)
YourroutersupportsVPNtunnelsforsecureLAN‐to‐LANaccess.TosetupaVPNthroughyourrouter:
1. Fromthenavigationpane,selectTunnels,IPsecTunnels.
2. Inthepanethatopens,clickAddTunnel.Aseriesofwizardpanelshelpsyouconfiguretheconnection.
3. Inthefirstpa
nel,enterthefollowinginformation:
IntheNamefield,typeanamefortheconnection.
Ifdesired,intheDescriptionfield,typeadescriptionfortheconnection.
ClickNext.
4. Inthenextpanel:
IntheRemoteWANIPfield,typetheIPaddressoftheremoteWAN.
IntheSavedNetworkdrop‐downlist,selectthedesirednetwork.Otherwiseyoucanmanuallydefine
thenetworkbycompletingtheNetworkRouteandNetworkMaskfields.
ClickNext.
5. Inthenextpanel:
InthePre‐SharedKeyfieldtypethepre‐sharedkeythatisagreeduponandsharedbytheVPN
endpoints.Youmustconfigurethiskeyatbothendpointsofthetunnel.
FromtheEncryptionMethoddrop‐downlist,selecttheencryptionmethod.3DESisrecommended.
Optionsinclude3DES,AES‐128,AES‐192,AES‐256.
IntheIKELifeTimefield,typethedurationforwhichtheISAKMPsecurityassociation(SA)lasts,from
successfulnegotiationtoexpiration.Thedefaultvalueisonehourandthemaximumis8hours.
IntheKeyLifefield,typethedurationforwhichtheIPSecSAlasts,fromsuccessfulnegotiationto
expiration.Thedefaultvalueisonehourandthemaximumis24hours.
IntheMaxRetriesfield,typethenumberofretriesfortheIPSectunnel.Enterzeroforunlimited
retries.
ToenabletheLocalIDandRemoteID,checkEnableUID(UniqueIdentifierString).Thenenterlocal
IDandremotestringidentifiers:
LocalID,typeastringidentifierforthelocalsecuritygateway.
RemoteID,typeastringidentifierfortheremotesecuritygateway.
ToenableIPCOMP,thecompressionalgorithm,checkCompression.
ToenablePerfectForwardSecrecy(PFS),aconceptinwhichthenewlygeneratedkeysareunrelated
totheolderkeys,checkPerfectForwardSecrecy.
ClickFinish.