Enterprise AV Home WiFi Mobile Wifi Support Shop Deals

Your BR500 router can connect to another BR500 over a secure site-to-site IPSec virtual private network (VPN) connection. Both BR500 routers must be running the same firmware, version 5.5.1.1 or later.

Your BR500 router can also connect to another router that supports IPSec. IPSec is a secure network protocol that authenticates and encrypts data sent through a VPN tunnel. IPSec uses either version one or version two of the Internet Key Exchange protocol (IKEv1 or IKEv2) to establish a secure connection.
 
To set up an IPSec VPN tunnel on your BR500 router:
  1. On a computer or mobile device that is connected to your BR500 router's network, access https://www.routerlogin.net.

    A login window opens.

  2. Enter the router user name and password.

    The user name is admin. If you did not change your router's password during setup, enter password. The user name and password are case-sensitive.

  3. On the router dashboard, select ADVANCED.
  4. Select IPSec VPN.
  5. Click the Add button.The IPSec policy settings appear on the right.
  6. Name the IPSec policy.
  7. Enter the WAN IP address or fully qualified domain name (FQDN) of the remote VPN router.
  8. Enter the LAN IP subnet address and mask of the remote VPN router.
  9. Enter the LAN IP subnet address and mask of the BR500 router.
  10. Enter a pre-shared key for the IPSec policy.The pre-shared key must be the same for both routers in the site-to-site VPN.
  11. Select IKEv1 or IKEv2.
  12. If you need to customize the Phase 1 and Phase 2 settings, click Advanced Settings.

    You can set up a VPN IPSec tunnel without changing these settings. However, you can customize these settings for different network or security configurations.

  13. (Optional) Set up your Phase-1 settings:
    1. Next to one or more Proposals lines, select an algorithm.

      You must use the same algorithms on both VPN routers.

    2. For the Exchange Mode, select Main Mode or Aggressive Mode. Aggressive Mode is only available on IKEv1.
    3. For the Negotiation Mode, select Initiator/Responder Mode or Initiator Mode.
      • Initiator/Responder Mode: The BR500 can both initiate a connection to the remote VPN router and respond to an IKE request from the remote VPN router. This is the default mode.
      • Responder Mode: The BR500 can respond to an IKE request from the remote VPN router.
    4. For SA Lifetime (seconds 60-604800), enter the time in seconds before the key must be re-established with the network.
    5. (Optional) To periodically check the connection and attempt to reconnect if the connection goes dead, check the box next to DPD (Dead Peer Detection) and enter a time interval between checks in seconds under DPD Interval (seconds 1-300).
  14. (Optional) Set up your Phase-2 settings:
    1. Next to one or more Proposals lines, select an algorithm.

      You must use the same algorithms on both VPN routers.

    2. For IKE1, Perfect Forward Secrecy (PFS) is enabled, and you can select a Diffie-Hellman (DH) group algorithm.
    3. For SA Lifetime (seconds 120-604800), enter the time in seconds before the key must be re-established with the network.
  15. Click the Apply button.
  16. Repeat the IPSec setup process on the other device on the VPN.

    If you customized the Phase 1 and Phase 2 settings, these settings must be the same on the remote VPN router.

Last Updated:07/07/2025 | Article ID: 000060839

This article applies to:

Recently Viewed Articles

    Our team is here to help!

    Phone
    Chat
    Email