
ADVANCED SET-UP
Machine Access Box RAS
DOC_DEV_RAS_User guide_A
Page 89
IPSec VPNs set-up
7.1
Overview
An IPSec VPN tunnel allows to connect two networks in a safe and transparent way : Each device of the first
network can exchange data with any device of the other network.
25 IPSec connections can be set by one ETIC router.
Glossary
The router which initiates the IPSec VPN is called the initiator; the other one is called the responder.
Preshared key authentication
Only one preshared key can be stored in one ETIC router; it is used by all the VPNs and also by the
L2TP/IPSec remote user connection.
Certificate authentication
The authentication of the two participants to the VPN connection can also be carried-out with certificates.
Coming from factory , a certificate produced by ETIC TELECOM is registered in the ETIC router.
Other kinds of X509 certificates can be added. (see the Set-up>Security>X509 certificate).
The certificate used by each participant to the VPN must be delivered by the same authority.
Setting-up an IPSec tunnel in the case where the source IP address is modified along the way from the
initiator to the responder router.
To provide a strong mutual authentication, each router checks the source IP address of the frames it
receives is the authentical IP address.
It is why, the IPSec tunnel requires a particular setup when the IP address of the initiator or the responder is
not fixed and / or when intermediate routers replace the source IP address by their own address (NAT).
It is what happens, in particular, in the case of cellular networks.
Two set-up solutions are possible :
Solution 1 : Use a certificate for authentication instead of a preshared key
Solution 2 : if the preshared key authentication method is used, an IKE code (IKE ID) needs to be assigned to
each router. See the IPSec set-up paragraph hereafter.
Summary of Contents for RAS-E
Page 8: ......
Page 44: ......
Page 64: ......
Page 96: ...ADVANCED SET UP Page 96 DOC_DEV_RAS_User guide_A Machine Access Box RAS ...
Page 126: ......
Page 132: ...ETIC TELECOM 13 chemin du vieux Chêne 38240 Meylan France contact etictelecom com ...