IPSec
769
Programming Operations Guide
Networks would have two networks configured as 10.10.10.0 with a mask 255.255.255.0 and
10.10.11.0 with a mask 255.255.255.0 and the Remote Accessible Networks would be 12.12.12.0
with a mask of 255.255.255.0. All packets that do not match these rules will be NATed and sent
out the interface and not through the tunnel. This is a useful configuration if access to both the
Internet and the other side of an IPSec tunnel is desired.
Dialup ISDN connections
When you are creating an IPSec tunnel over a Dialup ISDN connection, the endpoint must have a
fixed IP address.
Compatibility with Contivity Extranet Switch and Shasta 5000
When connecting to a Contivity Extranet Switch, you must disable Vendor ID and Compression
under Base Class on the Contivity Extranet Switch.
Business Communications Manager does not support the IPSec RIP implementation used by the
Contivity Extranet Switch. Use Static Routes when connecting to the Contivity Extranet Switch.
When connecting to a Shasta 5000, you must set the PFS to No on the Tunnel configuration of
Business Communications Manager.
IPSec and PPTP
The Remote Accessible Networks of an IPSec tunnel cannot be the same as a Destination Network
on a PPTP tunnel. The Remote Endpoint of an IPSec tunnel’s Remote Endpoint cannot be the
same as a Destination Endpoint on a PPTP tunnel.
Multiple IP Address restrictions
Although the Business Communications Manager supports the configuration of additional IP
addresses on its network interfaces, IPSec does not currently support the use of these additional IP
addresses for Branch Office Local Endpoint Addresses, Remote Endpoint Addresses or the
Destination IP Address for IPSec VPN Clients.
For more information about Multiple IP addresses, refer to
“Configuring multiple IP addresses for
the LAN interface” on page 671
.
Firewall rules for IPSec Branch Office and Remote User Tunnels
In order to allow IPSec packets through the firewall interface which blocks all incoming packets, a
number of rules must be configured. In addition to allowing the IPSec packets through, you must
also remember to create rules to allow the packets that come through the tunnel.
In the Branch office case, up to three rules must be created. One is for the key exchange protocol
(IKE), the other two are for the type of protocol used (ESP and/or AH).
Table 226
,
Table 227
and
Table 228
show the rules required (these are all inbound rules).
Summary of Contents for BCM 3.7
Page 4: ...4 Software licensing N0008589 3 3...
Page 32: ...32 Contents N0008589 3 3 W 937 Index 939...
Page 46: ...46 Tables N0008589 3 3...
Page 64: ...64 How to get help N0008589 3 3...
Page 90: ...90 Manually activating Telnet N0008589 3 3...
Page 116: ...116 Delayed system restart N0008589 3 3...
Page 194: ...194 Configuring a data module N0008589 3 3...
Page 276: ...276 Setting line telco features N0008589 3 3...
Page 310: ...310 Using COS passwords N0008589 3 3...
Page 364: ...364 Enhanced 911 E911 configuration N0008589 3 3...
Page 380: ...380 Renumbering DNs N0008589 3 3...
Page 398: ...398 Saving wizard pages on your computer N0008589 3 3...
Page 458: ...458 Voice Mail settings N0008589 3 3...
Page 488: ...488 Setting system telco features N0008589 3 3...
Page 508: ...508 Other programming that affects public networking N0008589 3 3...
Page 522: ...522 PRI networking using Call by Call services N0008589 3 3...
Page 592: ...592 Monitoring Hunt groups N0008589 3 3...
Page 636: ...636 Configuring Double Density N0008589 3 3...
Page 640: ...640 Using the Network Update Wizard N0008589 3 3...
Page 666: ...666 Importing and Exporting DHCP data N0008589 3 3...
Page 722: ...722 Restarting the router N0008589 3 3...
Page 726: ...726 Important Web Cache considerations N0008589 3 3...
Page 748: ...748 Configuring an Interface with NAT N0008589 3 3...
Page 794: ...794 IPSec N0008589 3 3...
Page 818: ...818 Configuring the Policy Agent characteristics N0008589 3 3...
Page 832: ...832 Firewall rules for Business Communications Manager with Dialup interfaces N0008589 3 3...
Page 876: ...876 ISDN Programming N0008589 3 3...
Page 1004: ...1004 Index N0008589 3 3...