Virtual Private Networks (VPNs) 12-23
■
Select
IP Profile Parameters
and press Return. The IP Profile Parameters screen appears.
■
Enter the
Remote IP Address
and
Remote IP Mask
for the host to which you want to tunnel.
Allowing VPNs through a Firewall
An administrator interested in securing a network will usually combine the use of VPNs with the use of a firewall
or some similar mechanism. This is because a VPN is not a complete security solution, but rather a component
of overall security. Using a VPN will add security to transactions carried over a public network, but a VPN alone
will not prevent a public network from infiltrating a private network. Therefore, you should combine use of a
firewall with VPNs, where the firewall will secure the private network from infiltration from a public network, and
the VPN will secure the transactions that must cross the public network.
A strict firewall may not be provisioned to allow VPN traffic to pass back and for th as needed. In order to ensure
that a firewall will allow a VPN, cer tain attributes must be added to the firewall's provisioning. The provisions
necessar y var y slightly between ATMP and PPTP, but both protocols operate on the same basic premise: there
are control and negotiation operations, and there is the tunnelled traffic that carries the payload of data
between the VPN endpoints. The difference is that ATMP uses UDP to handle control and negotiation, while
PPTP uses TCP. Then both ATMP and PPTP use GRE to carr y the payload.
For PPTP negotiation to work, TCP packets inbound and outbound destined for por t 1723 must be allowed.
Likewise, for ATMP negotiation to work, UDP packets inbound and outbound destined for por t 5150 must be
allowed. Source por ts are dynamic, so, if possible, make this flexible, too. Additionally, PPTP and ATMP both
require a firewall to allow GRE bi-directionally.
The following sections illustrate a sample filtering setup to allow either PPTP or ATMP traffic to cross a firewall:
■
PPTP example on page 12-24
■
ATMP example on page 12-27
Make your own appropriate substitutions. For more information on filters and firewalls, see
Chapter 13,
“Security.”
.
IP Profile Parameters
Address Translation Enabled: Yes
NAT Map List... Easy-PAT
NAT Server List... Easy-Servers
Local WAN IP Address: 0.0.0.0
Remote IP Address: 173.167.8.10
Remote IP Mask: 255.255.0.0
Filter Set...
Remove Filter Set
Receive RIP: Both
Enter a subnet mask in decimal and dot form (xxx.xxx.xxx.xxx).
Summary of Contents for 4752
Page 1: ...Netopia 4752 SDSL Integrated Access Device Administration Guide ...
Page 12: ...Administration Guide ...
Page 18: ...2 4 Administration Guide ...
Page 30: ...4 8 Administration Guide ...
Page 34: ...5 4 Administration Guide ...
Page 40: ...6 6 Administration Guide ...
Page 58: ...Administration Guide ...
Page 82: ...9 24 Administration Guide ...
Page 110: ...10 28 Administration Guide ...
Page 172: ...12 30 Administration Guide ...
Page 206: ...13 34 Administration Guide ...
Page 236: ...Administration Guide ...
Page 242: ...A 6 Administration Guide ...
Page 258: ...C 14 Administration Guide ...
Page 264: ...E 4 Administration Guide ...
Page 284: ...2 Administration Guide ...