Ubigate iBG2016 Configuration Guide/Ed.00
© SAMSUNG Electronics Co., Ltd.
287
Supporting Remote User Access Example
The following example demonstrates how to configure a router to be an IPSec
VPN server using user group method with extended authentication(XAUTH)
for remote VPN clients. The client could be any standard IPSec VPN client.
In this example, the client needs to access the corporate private network
10.0.1.0/24 through the VPN tunnel. The security requirements are as follows:
y
Phase 1: 3DES with SHA1, Xauth(Radius PAP)
y
Phase 2: IPSec ESP tunnel with AES256 and HMAC-SHA1
1.
Configure a WAN bundle of network type untrusted.
Router/configure# interface bundle wan1
Router/configure/interface/bundle wan1# link t1 0/2/0
Router/configure/interface/bundle wan1# encapsulation ppp
Router/configure/interface/bundle wan1# ip address
172.16.0.1 24
Router/configure/interface/bundle wan1# crypto untrusted
Router/configure/interface/bundle wan1# exit
2.
Configure the Ethernet interface with trusted network type.
Router/configure# interface ethernet 0/1
message: Configuring existing Ethernet interface
Router/configure interface/ethernet(0/1)# ip address
10.0.1.1 24
Router/configure/interface/ethernet(0/1)# crypto trusted
Router/configure/interface/ethernet(0/1)# exit
Corporate Headquarters
10.0.1.0/24
Router #1
VPN Server
172.16.0.1
IPSec Tunnel
VPN Client 1
Local Address: Dynamic
[email protected]
VPN Client 2
Local Address: Dynamic
[email protected]
IPSec Tunnel
Summary of Contents for Ubigate iBG2016
Page 1: ......
Page 16: ...INTRODUCTION XIV SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 34: ......
Page 62: ...CHAPTER 4 System Logging 28 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 70: ......
Page 108: ......
Page 140: ...CHAPTER 4 RIP 104 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 156: ...CHAPTER 6 BGP 120 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 180: ...CHAPTER 8 VRRP 144 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 264: ...CHAPTER 10 QoS 228 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 272: ......
Page 298: ...CHAPTER 3 Firewall NAT 248 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 356: ...CHAPTER 5 IPSEC 306 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 358: ......
Page 744: ...EQBD 000071 Ed 00 ...