Your PR60X router can connect to another PR60X over a secure site-to-site IPSec virtual private network (VPN) connection.
Your PR60X router can also connect to another router that supports IPSec. IPSec is a secure network protocol that authenticates and encrypts data sent through a VPN tunnel. IPSec uses either version one or version two of the Internet Key Exchange protocol (IKEv1 or IKEv2) to establish a secure connection.
To set up an IPSec VPN tunnel on your PR60X router:
- On a computer or mobile device that is connected to your PR60X router's network, access https://www.routerlogin.net. Your browser might display a security message, which you can ignore.
A login window opens.
- Enter the router user name and password.
The user name is admin. If you did not change your router's password during setup, enter password. The user name and password are case-sensitive.
- On the router dashboard, select VPN.
- Select IPSec Profiles.
- Click the + button to add a new IPSec Profile.
- Name the IPSec Profile.
- Select IKEv1 or IKEv2.
- If you need to customize the Phase 1 and Phase 2 settings:
You can set up a VPN IPSec tunnel without changing these settings. However, you can customize these settings for different network or security configurations.
- (Optional) Set up your Phase-1 settings:
- Next to one or more Proposals lines, select an algorithm.
You must use the same algorithms on both VPN routers.
- For SA Lifetime (seconds 60-604800), enter the time in seconds before the key must be re-established with the network.
- Next to one or more Proposals lines, select an algorithm.
- (Optional) Set up your Phase-2 settings:
- Next to one or more Proposals lines, select an algorithm.
You must use the same algorithms on both VPN routers.
- For SA Lifetime (seconds 120-604800), enter the time in seconds before the key must be re-established with the network.
- Next to one or more Proposals lines, select an algorithm.
- Click Apply.
- Next, click the Site-to-Site button to create the site-to-site tunnel.
- Click the + button.
- Name the connection under the Connection Name field.
- Select the IPSec Profile that was previously created from the IPSec Profile menu.
- Enter the remote end point. This would be the remote connections WAN IP address.
- In the IKE Authentication Method section, enter a Pre-Shared Key. This Pre-shared Key must match the key configured on the other site.
- Enter the local WAN IP address or fully qualified domain name (FQDN) of the VPN router.
- Enter the local LAN IP subnet address and mask of the router.
- Enter the remote WAN IP address under the Remote Identifier field.
- Enter the remote networks accessible LAN network under the Enter IP Address and Subnet Mask.
- Enter the dead peer detection settings under the DPD Options field. DPD options determines how long of a delay before detecting the connection as dead and what actions to take when the tunnel is not responding.
- Click the Apply button.
- Repeat the IPSec setup process on the other device on the VPN.
- After the tunnel has been created. Check the status of the tunnel under the Site-to-Site page.
If the tunnel is not reporting UP, please check the IPSec settings to make sure the settings are correct.