SETUP
Page 28
DOC_DEV_Router setup guide_A
6
IPSec VPNs setup
6.1
Overview
An IPSec VPN tunnel allows to connect two networks in a safe and transparent way : Each device of the first
network can exchange data with any device of the other network.
10 IPSec connections can be set by one IPL or RAS router.
100 IPSec connections can be set by one SIG router.
500 IPSec connections can be set by one SIG VM router.
•
Glossary
The router which initiates the IPSec VPN is called the initiator; the other one is called the responder.
•
Preshared key authentication
Only one preshared key can be stored in one Router; it is used by all the VPNs and also by the L2TP/IPSec
remote user connection.
•
Certificate authentication
The authentication of the two participants to the VPN connection can also be carried-out with certificates.
Coming from factory , a certificate produced by ETIC TELECOM is registered in the Router.
Other kinds of X509 certificates can be added. (see the Set-up>Security>X509 certificate).
The certificate used by each participant to the VPN must be delivered by the same authority.
•
Setting-up an IPSec tunnel in the case where the source IP address is modified along the way from the
initiator to the responder router.
To provide a strong mutual authentication, each router checks the source IP address of the frames it
receives is the authentical IP address.
It is why, the IPSec tunnel requires a particular setup when the IP address of the initiator or the responder is
not fixed and / or when intermediate routers replace the source IP address by their own address (NAT).
It is what happens, in particular, in the case of cellular networks.
Two set-up solutions are possible :
Solution 1 : Use a certificate for authentication instead of a preshared key
Solution 2 : if the preshared key authentication method is used, an IKE code (IKE ID) needs to be assigned to
each router. See the IPSec set-up paragraph hereafter.
Summary of Contents for RAS Series
Page 1: ...DOC_DEV_Router setup guide_A RAS IPL SIG _________________ SETUP GUIDE _________________ ...
Page 8: ......
Page 14: ......