
Installation Manual References
5.9.3 Installing SIP Phones at a Remote Site
5.9.4 Installing IP Phones at a Remote Site with a Built-in Media Relay Gateway
Feature Guide References
5.2.3 Peer-to-Peer (P2P) Connection
8.6.19 IPsec Pass-through
Description
For VPN packets that use IPsec and are sent and received from a specified device on the LAN, you can
configure settings so that (1) the port number is not changed when these packets are sent and received and
(2) these packets are allowed to cross the LAN–WAN boundary uninhibited.
Only 1 device on the LAN can be designated as the IPsec pass-through device.
Setting
Description
Application
IPsec
Protocol/Protocol number
ESP
/ 50
Port number
UDP/500: ISAKMP
UDP/4500: NAT-T
A VPN that uses IPsec is a tunnelling protocol, so the send/receive port number for packets additionally
indicates which tunnelling protocol the packets are using. If the port number is changed by the dynamic NAPT
(IP masquerade) feature, the information that indicates the tunnelling protocol will be lost, and end-to-end
communication will be impossible.
To allow end-to-end communication, specified packets from a specified device are allowed to pass through
the WAN–LAN boundary without having their port number changed.
Conditions
•
The IPsec pass-through feature cannot be used together with the PBX’s IPsec feature or the VPSS feature.
This is because when IPsec packets pass through to the LAN, they cannot be distinguished from VPN
(IPsec) packets for the KX-NS1000.
•
Communication across the WAN–LAN boundary is subject to the following conditions:
–
IKE
must be able to be initiated from the WAN side.
–
The first ESP
packet must be able to be sent from either the LAN side or the WAN side.
*1
ESP: Encapsulating Security Payload
*2
ISAKMP: Internet Security Association Key Management Protocol
*3
NAT-T: NAT Traversal
*4
IKE: Internet Key Exchange
PC Programming Manual References
27.11 Router Configuration—VPN—[3-3] Pass Through
Installation Manual
391
8.6.19 IPsec Pass-through
Summary of Contents for KX-NS1000
Page 40: ...40 Installation Manual 1 4 Data Security ...
Page 76: ...76 Installation Manual 2 3 3 System Capacity ...
Page 108: ...108 Installation Manual 3 1 3 Using CTI Applications ...
Page 267: ...the priority Installation Manual 267 5 8 3 Setting LLDP Parameters ...
Page 312: ...312 Installation Manual 5 12 Automatic Configuration of Mailboxes ...
Page 318: ...318 Installation Manual 6 2 Methods of Stacking PBXs ...
Page 332: ...332 Installation Manual 7 1 6 Troubleshooting by Error Log ...
Page 400: ...400 Installation Manual 8 6 26 WAN Port Mirroring ...
Page 414: ...414 Installation Manual 9 3 7 PCMPR Software File Version 004 1xxxx ...