142
Chapter 7 Configuring control tunnels
NN46110-500
1
Initiate a Telnet session to the customer’s Nortel VPN Router.
2
Enter the appropriate control create string, following the required control
create parameters already described. A sample string follows:
control create boston bostoncleveland 132.19.2.20 132.19.2.30
192.168.2.3 192.168.20.0 255.255.255.0
Management Only (a special control tunnel filter) is used by default with
control tunnels to maximize security.
3
To view Help, enter control help create. These are control create parameters
that you must enter:
CONTROL CREATE <
name>
<
password
> <
MGMT/Local_P
> <
Local_endpoint
>
<
Remote_endpoint
> <
Remote_Subnet_Address
> <
Remote_Subnet_Mask
>
If you are using the local Nortel VPN Router current Management IP address
(132.19.2.20)
rather than a substitute, then the network address translation
feature is unnecessary. If not, enable control on the remote Nortel VPN Router
and enter the control address through the command line interface. If you enter
an address other than the management IP address (MGMT), NAT creates a
NAT set with a static rule. The NAT set is called Control plus the name of the
connection (for example, Control Boston). This also creates a network
definition that is named Control and the name of the connection. The network
definition contains the NAT management address. In this case, the branch
office connection automatically fills in the correct NAT rule and accessible
network.
When using the control create commands, you must enter them in a
complete string
. The Nortel VPN Router that you are controlling sets a
management only filter by default that restricts access to the management IP
address only. You can verify the control tunnel connection from the Profiles
>
Branch Office: Control Tunnels connection field.
After you configure the local Nortel VPN Router, you must configure the Nortel
VPN Router located at the remote site. Complete the following steps to define the
branch office connection for the remote Nortel VPN Router.
Adding a group
To create a new group :
1
Select
Profiles > Branch Office
.
2
In
Groups
section, click
Add.
The
Add Group
window appears.
Summary of Contents for Contivity 1050
Page 10: ...10 Contents NN46110 500 ...
Page 14: ...14 Tables NN46110 500 ...
Page 22: ...22 Preface NN46110 500 ...
Page 58: ...58 Chapter 2 Getting started NN46110 500 ...
Page 74: ...74 Chapter 3 Setting up the Nortel VPN Router 1010 1050 and 1100 NN46110 500 ...
Page 90: ...90 Chapter 4 Configuring user tunnels NN46110 500 ...
Page 118: ...118 Chapter 5 Configuring the system NN46110 500 ...
Page 162: ...162 Chapter 8 Configuring IPSec mobility and persistent mode NN46110 500 ...
Page 164: ...164 Branch office quick start template NN46110 500 ...
Page 178: ...178 Index NN46110 500 W Web browser interface 50 Web interface options 53 Welcome display 56 ...