Configuration Examples - Page 43
Part 2 - IPSec configuration
With Part 1 completed (see page 41), perform the following:
Task Description
Step 1
Install the IPSec Licence.
Licence name – IPSec Tunneling.
An IPSec Licence is required per IP Office. Make
sure the IPSec licences are valid on both PC’s.
Step 2
For IPO_CO create an IPSec tunnel
(see page 24).
Main tab
•
Name = IPSec_Tunnel
•
Local IP Address = 217.37.65.126
•
Local IP Mask = 255.255.255.255
•
Gateway - <LocalInterface>
•
Remote IP Address = 217.37.69.116
•
Remote IP Mask = 255.255.255.255
•
Gateway = 217.37.69.116
A name for the IPSec tunnel is required.
The Local IP Address/Mask is the range of IP
addresses you want to secure through the tunnel.
The Remote IP Address is the remote networks IP
address range that we want to secure through the
tunnel.
The Remote IP Mask is the remote mask.
The Gateway is the
tunnel endpoint
. Hence, for
IPO_CO, the remote Gateway will be 217.37.69.116,
which is the IP address of Branch No. 1.
Step 3
For IPO_CO perform the following in
the IKE Polices tab:
•
Shared Secret = password
•
Exchange Type = ID port
•
Encryption = DES
•
Authentication = MD5
•
DH Group = Group 2
•
Life Type = Seconds
•
Life = 86400
Both tunnel endpoints must have the same-shared
secret.
Encryption set to DES.
Authentication set to MD5
Diffie-Hellman Group = Group 2
This is the time period before a new key is generated
(86400 represents one day in seconds).
Step 4
For IPO_CO, perform the following in
the IPSec Policies tab:
•
Protocol = ESP
•
Encryption = DES
•
Authentication = MD5
•
Life Type = Seconds
•
Life = 86400
Protocol set to Encapsulating Security Payload.
Encryption set to DES
Authentication set to MD5
This is the time period before a new key is generated
(86400 represents one day in seconds).
Step 5
For Branch No. 1 create an IPSec
tunnel.
Main tab
•
Name = IPSec_Tunnel
•
Local IP Address = 217.37.69.116
•
Local IP Mask = 255.255.255.255
•
Gateway - <LocalInterface>
•
Remote IP Address = 217.37.65.126
•
Remote IP Mask = 255.255.255.255
•
Gateway = 217.37.65.126
A name for the IPSec tunnel is required.
The Local IP Address/Mask is the range of IP
addresses you want to secure through the tunnel.
The Remote IP Address is the remote networks IP
address range that we want to secure through the
tunnel. The Remote IP Mask is the remote mask.
The Gateway is the
tunnel endpoint
. Hence, for
Branch No. 1, the remote Gateway will be
217.37.65.116, which is the IP address of IPO_CO.
IP Office (R3.0) Virtual Private Networking
Configuration Examples - Page 43
40DHB0002UKER Issue 3 (4th February 2005)
Part 2: VPN configuration