IPsec Support• IPsecSelecting Enable will launch the IPsec process and start all enabled tunnels. Selecting Disable will stop all tunnelsand shutdown the IPsec process. Note that all enabled tunnels will be launched automatically when the unitconnects to the cellular carrier.• NAT ModeDetermines how packets are addressed. Selecting Bypass will allow packets coming from Local Subnet addressesthrough the NAT firewall unchanged. This may be sufficient when traffic only travels from Local Subnet to RemoteSubnet. (LAN Settings » Bind to Eth IP may need to be enabled to make sure that packets generated by Vanguardservices appear to originate from a Local Subnet address.) NAT changes the source address to match the Status »PPP IP Address. NAT-Traversal enables the NAT-T protocol which can support traffic beyond just the Local andRemote Subnets.Tunnel MonitorTo supplement/complement Dead Peer Detection, tunnels can be monitored by sending periodic pings, with thetunnels being restarted if the pings repeatedly fail. Tunnel monitoring is controlled by the following parameters.• IP Address 1 & IP Address 2Up to two addresses may be entered. Only those tunnels where the IP address matches the Remote IP Address orbelongs to the Local Subnet or Remote Subnet are monitored. A value of 0.0.0.0 disables monitoring.• DelayHow often, in seconds, to send pings over the tunnel.• Fail count thresholdThe number of successive pings that need to fail to cause the tunnel to be restarted.• Success count thresholdThe number of successive pings that need to succeed for the tunnel to be considered “up” and for the process ofcounting failed pings to begin.Tunnel Configuration• Tunnel ItemTunnel number, starts from 1 and increments for each new tunnel. To update an existing tunnel, use itscorresponding number from the tunnel table. To add a new tunnel, add one to the item number of the tunnel listedlast in the Tunnel Table.• LabelThis is a label to identify a tunnel and corresponds to the name specified for the remote endpoint.• Remote IP AddressThe IP address of the remote endpoint of the tunnel.Vanguard 3000 Series Multicarrier Cellular Data Modem & IP Router PN 001-7300-100 Rev. B | Page 58