
216
Chapter 13 VPN
NN47922-500
NAT traversal solves the problem by adding a UDP port 500 header to the IPSec
packet. The NAT router forwards the IPSec packet with the UDP port 500 header
unchanged. VPN switch B checks the UDP port 500 header and responds. VPN
switches A and B build a VPN connection.
NAT Traversal configuration
Enable or disable NAT traversal in the
VPN Branch Office Rule Setup
screen
(see
). For NAT traversal to work, you must:
•
Use ESP security protocol (in either transport or tunnel mode)
•
Use IKE keying mode
•
Enable NAT traversal on both IPSec endpoints
In order for VPN switch A (see
) to receive an initiating
IPSec packet from VPN switch B, set the NAT router to forward UDP port 500 to
VPN switch A.
Preshared key
A preshared key identifies a communicating party during a phase 1 IKE
negotiation (see
for more information). It is called
preshared because you have to share it with another party before you can
communicate with them over a secure connection. For Contivity Client VPN
connections, the Business Secure Router generates the preshared key from the
username and password.
Configuring Contivity Client VPN Rule Setup
Select one of the VPN rules in the
VPN Summary
screen and click
Edit
to
configure the rule’s settings. If the
Branch Office
screen is displayed, select
Contivity Client
from the
Connection Type
list box. The
VPN Contivity
Client Rule Setup
screen is shown in
Summary of Contents for BSR222
Page 28: ...28 Tables NN47922 500 ...
Page 50: ...50 Chapter 2 Introducing the WebGUI NN47922 500 ...
Page 66: ...66 Chapter 3 Wizard setup NN47922 500 ...
Page 92: ...92 Chapter 5 System screens NN47922 500 ...
Page 104: ...104 Chapter 6 LAN screens NN47922 500 ...
Page 154: ...154 Chapter 9 Static Route screens NN47922 500 ...
Page 196: ...196 Chapter 11 Firewall screens NN47922 500 ...
Page 212: ...212 Chapter 13 VPN NN47922 500 Figure 68 Summary IP Policies ...
Page 256: ...256 Chapter 13 VPN NN47922 500 Figure 82 VPN Client Termination advanced ...
Page 260: ...260 Chapter 13 VPN NN47922 500 ...
Page 264: ...264 Chapter 14 Certificates NN47922 500 Figure 84 My Certificates ...
Page 290: ...290 Chapter 14 Certificates NN47922 500 Figure 95 Trusted remote host details ...
Page 314: ...314 Chapter 16 IEEE 802 1x NN47922 500 ...
Page 318: ...318 Chapter 17 Authentication server NN47922 500 Figure 107 Local User database edit ...
Page 326: ...326 Chapter 17 Authentication server NN47922 500 ...
Page 374: ...374 Chapter 20 Logs Screens NN47922 500 Figure 151 Log settings ...
Page 384: ...384 Chapter 20 Logs Screens NN47922 500 ...
Page 402: ...402 Chapter 22 Maintenance NN47922 500 Figure 170 Restart screen ...