11
Nortel VPN Router Configuration — Basic Features
Figures
Figure 1
Typical PDN . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 26
Figure 2
VPN service models . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 27
Figure 3
Sample IP addressing scheme . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 30
Figure 4
MVA on separate subnet from private physical interfaces . . . . . . . . . . . . 32
Figure 5
MVA on same subnet as private physical interface . . . . . . . . . . . . . . . . . 33
Figure 6
MVA managing from a remote PC . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 33
Figure 7
Deployment Scenario . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 41
Figure 8
Default configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 60
Figure 9
Tunnel connection configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 75
Figure 10
Inverse Split Tunneling . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 85
Figure 11
Inverse Split Tunneling . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 86
Figure 12
Edit > IPsec page for wildcard . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 88
Figure 13
LAN-to-Nortel VPN Router connection . . . . . . . . . . . . . . . . . . . . . . . . . . . 93
Figure 14
LAN > Interfaces window . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 98
Figure 15
LAN Interfaces > Add IP Address window . . . . . . . . . . . . . . . . . . . . . . . . 99
Figure 16
Asynchronous data over TCP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 105
Figure 17
SSH Server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 112
Figure 18
Allowed Services window . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 114
Figure 19
Typical branch office environment . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 120
Figure 20
Branch-to-branch with a firewall and a router . . . . . . . . . . . . . . . . . . . . . 121
Figure 21
Indirectly connected branch offices . . . . . . . . . . . . . . . . . . . . . . . . . . . . 122
Figure 22
VPN DNS . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 125
Figure 23
Failover example . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 126
Figure 24
Load balancing example . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 127
Figure 25
Setting up a branch office configuration . . . . . . . . . . . . . . . . . . . . . . . . . 129
Figure 26
Sample branch office configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . 134
Figure 27
Branch office control tunnel . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 138
Figure 28
Sample control tunnel environment . . . . . . . . . . . . . . . . . . . . . . . . . . . . 139
Figure 29
Example configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 148
Summary of Contents for Contivity 1050
Page 10: ...10 Contents NN46110 500 ...
Page 14: ...14 Tables NN46110 500 ...
Page 22: ...22 Preface NN46110 500 ...
Page 58: ...58 Chapter 2 Getting started NN46110 500 ...
Page 74: ...74 Chapter 3 Setting up the Nortel VPN Router 1010 1050 and 1100 NN46110 500 ...
Page 90: ...90 Chapter 4 Configuring user tunnels NN46110 500 ...
Page 118: ...118 Chapter 5 Configuring the system NN46110 500 ...
Page 162: ...162 Chapter 8 Configuring IPSec mobility and persistent mode NN46110 500 ...
Page 164: ...164 Branch office quick start template NN46110 500 ...
Page 178: ...178 Index NN46110 500 W Web browser interface 50 Web interface options 53 Welcome display 56 ...