background image

Barricade Plus

VPN IPSEC & PPTP

Configuration Guide

 
 

The Information in this guide applies to the:

 

     

Barricade™ Plus Cable/DSL Broadband Router (SMC7004FW)

     

Barricade™ Plus Wireless Cable/DSL Broadband Router (SMC7004WFW) 

 
 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

NEXT – Table of Contents

Summary of Contents for 7004FW - annexe 2

Page 1: ...VPN IPSEC PPTP Configuration Guide The Information in this guide applies to the Barricade Plus Cable DSL Broadband Router SMC7004FW Barricade Plus Wireless Cable DSL Broadband Router SMC7004WFW NEXT Table of Contents ...

Page 2: ...able DSL Broadband Router This document is divided into the following sections 1 Installing Virtual Private Network Protocols Windows 95 98 98SE Windows Me Windows NT Windows 2000 XP 2 Configuring your MS PPTP Client to Connect to the Barricade Plus 3 Configuring your Barricade Plus as a PPTP Client 4 Configuring your Barricade Plus as a PPTP Server 5 Barricade Plus IPSec Tunnel Configuration 6 Gl...

Page 3: ...This section outlines the process for installing the necessary VPN protocols on the following operating systems Windows 95 98 98SE Windows Me Windows NT Windows 2000 XP Before you begin this configuration process please verify that you have the following Original Licensed Windows CD ...

Page 4: ... 1 Click on the Start button then choose Settings then select Control Panel Figure 1 0 Step 2 Locate and double click the Add Remove Programs icon Figure 1 1 Step 3 Click on the Windows Setup tab and highlight the Communication component then click on the Details button ...

Page 5: ...Figure 1 2 Step 4 In the Communication dialog box verify that the following 2 options are selected Dial Up Networking Virtual Private Networking ...

Page 6: ...Figure 1 3 Figure 1 4 When you have verified or selected these 2 options click the OK button to save the ...

Page 7: ...og box then click the Cancel button again to close the Add Remove Programs dialog box Skip to Section 2 Step 5 The Communications option should now be checked Click the OK button to save this change and close the Add Remove Programs dialog box Figure 1 5 Step 6 If prompted please insert your Windows CD to copy the required system files Figure 1 6 ...

Page 8: ...Figure 1 7 Step 7 When prompted with the dialog box below click the Yes button to reboot your computer and complete the installation process Figure 1 8 ...

Page 9: ...Windows Me Step 1 Click on the Start button then choose Settings then select Control Panel Figure 1 0 Step 2 Locate and double click the Dial Up Networking icon Figure 1 1 Step 3 Click on the Windows Setup tab and highlight the Communication ...

Page 10: ...component then click on the Details button Figure 1 2 Step 4 In the Communication dialog box verify that the following 2 options are selected Dial Up Networking Virtual Private Networking ...

Page 11: ...Figure 1 3 Figure 1 4 ...

Page 12: ...el button to close the Communications dialog box then click the Cancel button again to close the Add Remove Programs dialog box Skip to Section 2 Step 5 The Communications option should now be checked Click the OK button to save this change and close the Add Remove Programs dialog box Figure 1 5 Step 6 If prompted please insert your Windows CD to copy the required system files Figure 1 6 ...

Page 13: ...Figure 1 7 Step 7 When prompted with the dialog box below click the Yes button to reboot your computer and complete the installation process Figure 1 8 ...

Page 14: ...BACK Windows Me NEXT Windows 2000 XP Windows NT Step 1 Click on the Start button then choose Settings then select Control Panel Figure 1 0 Step 2 Double click Network Figure 1 1 ...

Page 15: ...Figure 1 2 Step 3 On the Protocols tab click Add and select Point to Point Tunneling Protocol Then press OK ...

Page 16: ...ill initialize You must add at least one VPN port as a port in the RAS setup interface Figure 1 4 Figure 1 5 Step 5 At this time specify which protocols you want to run for that VPN port You can install up to 256 VPN ports Each VPN can be connected to a network Make sure that at ...

Page 17: ...least one VPN is configured for dial out Figure 1 6 Step 6 Press Close and restart the machine when requested to do so Figure 1 7 ...

Page 18: ... XP Windows 2000 and Windows XP already have the required VPN communication components installed Please verify that you can connect to the Internet either through a dial up connection or through a LAN If you can connect to the Internet please go to the Section 2 ...

Page 19: ...n outlines the process for configuring a PPTP client on the following operating systems Windows 95 98 98SE Windows Me Windows NT Windows 2000 Windows XP Before you begin this configuration process please verify that you have the following IP Address of the Barricade Plus Router you are connecting to ...

Page 20: ...on your Desktop Step 2 In the My Computer window locate and double click the Dial Up Networking icon to launch the Welcome to Dial Up Networking wizard Figure 1 0 NOTE If the network wizard does not prompt you locate and click on the Make a New Connection icon to launch it Step 3 Click Next to start the Wizard ...

Page 21: ...ame for this VPN connection and Verify that you have the Microsoft VPN Adapter selected under the Select a device drop down menu Then click the Next button to continue Figure 1 2 Step 5 In the Host name or IP Address text box enter the WAN IP address of the ...

Page 22: ... you have completed the Make New Connection wizard click the Finish button to save this configuration Step 7 Double click the My Computer icon on your Desktop Step 8 Locate and double click the Dial Up Networking icon Figure 1 4 Step 9 In the Dial Up Networking window you will see the new VPN connection that ...

Page 23: ...d with the Connect To dialog box shown below please provide and verify the following information Username Password The VPN server text box has WAN IP address of the Barricade Plus you are connecting to To connect to the Barricade Plus VPN server click the Connect button to initialize the VPN connection ...

Page 24: ...isplayed in the system tray Once you are connected you should see two new monitor icons in the system tray and you will be able to access the computers on the remote network as if they were on your local LAN You can double click on the two linked monitors to view properties of the VPN tunnel Figure 1 7 ...

Page 25: ...d then click the Dial Up Networking link on the bottom left hand corner of the window Figure 1 0 Step 2 A Welcome window should appear Click Next to continue Figure 1 1 Step 3 If this is your first time configuring a VPN session you will be asked to enter your area code Please do so and press Close to continue ...

Page 26: ...e 1 2 Step 4 Enter a name for the VPN connection you wish to establish and click Next i e Barricade VPN Figure 1 3 Step 5 Enter the WAN IP address of the Barricade Plus you wish to connect to and click Next ...

Page 27: ... password that the Administrator of the remote network has given you Verify that the VPN Server field has the correct WAN IP address Then press the Connect button Note Be sure to enter this correctly as you will NOT be able to connect without the correct login data Once you are connected you should see two new monitor icons in the system tray and you will be able to access the computers on the rem...

Page 28: ...tunnel Figure 1 6 Figure 1 7 ...

Page 29: ...e click on the My Computer icon on your Desktop Then double click the Dial up Networking icon Figure 1 0 Step 2 If this is your first time configuring a VPN session you will be asked to enter your area code Please do so and press Close to continue Figure 1 1 ...

Page 30: ... entry in the Phonebook Press OK to continue Figure 1 2 Step 4 Enter a name for this entry and click the Next button i e Barricade VPN Figure 1 3 Step 5 Enter the WAN IP Address of the Barricade Plus that you are connecting to and click Next ...

Page 31: ...zard Figure 1 5 Step 7 Now you can review the settings you configured and choose to Dial the PPTP Server The Phone number preview section should show the WAN IP address of the Barricade Plus you are connecting to Press Dial to continue and connect ...

Page 32: ... OK button Note Be sure to enter this correctly as you will NOT be able to connect without the correct login data Figure 1 7 Once you are connected you should see two new monitor icons in the system tray and you will be able to access the computers on the remote network as if they were on your local LAN You can double click on the two linked monitors to view properties of the VPN tunnel ...

Page 33: ...Figure 1 8 ...

Page 34: ...ws 2000 Step 1 Right click the My Network Places icon on your desktop and click Properties Figure 1 0 Step 2 Double click Make New Connection Figure 1 1 Step 3 If this is your first time configuring a VPN session you may be asked to enter ...

Page 35: ...your area code Please do so and press OK to continue Figure 1 2 Step 4 A wizard will appear Please click Next to continue Figure 1 3 ...

Page 36: ...t the Connect to a private network through the Internet option and click Next Figure 1 4 Step 6 Enter the WAN IP address of the Barricade Plus that you wish to establish a connection with Then click Next Figure 1 5 ...

Page 37: ...ep 8 You have completed the VPN client setup Click Finish to exit Step 9 Enter the username and password that the Administrator of the remote network has given you Verify that the VPN Server field has the correct WAN IP address Then press the Connect button Note Be sure to enter this correctly as you will NOT be able to connect without the correct login data ...

Page 38: ...ld see two new monitor icons in the system tray and you will be able to access the computers on the remote network as if they were on your local LAN You can double click on the two linked monitors to view properties of the VPN tunnel Figure 1 8 ...

Page 39: ...Figure 1 9 ...

Page 40: ... Barricade Plus PPTP Client Windows XP Step 1 Go into the Control Panel Figure 1 0 Step 2 Click the Network and Internet Connections link Figure 1 1 Step 3 Click the Create a connection to the network at your workplace link ...

Page 41: ...gure 1 2 Step 4 Select the Virtual Private Network connection option and click Next to continue Figure 1 3 Step 5 Enter a name for the VPN connection you wish to establish and click Next i e Barricade VPN ...

Page 42: ...Figure 1 4 Step 6 Enter the WAN IP address of the Barricade Plus that you wish to establish a connection with Then click Next ...

Page 43: ...ction that you just created Double click on this connection Figure 1 7 Step 10 Enter the username and password that the Administrator of the remote network has given you Verify that the VPN Server field has the correct WAN IP address Then press the Connect button Note Be sure to enter this correctly as you will NOT be able to connect without the correct login data Once you are connected you should...

Page 44: ...ou will be able to access the computers on the remote network as if they were on your local LAN You can double click on the two linked monitors to view properties of the VPN tunnel Figure 1 8 Figure 1 9 ...

Page 45: ...l to a number between 2 and 254 Step 1 Open up your web browser and type in the IP Address of your Barricade Plus Step 2 Enter your password to log into the router and then go into the Advanced Setup Step 3 Click on the link for VPN on the left Then click PPTP Step 4 The router allows you to configure up to 20 different PPTP VPN accounts Click the Edit link for the first account and then you will ...

Page 46: ...ays be zero because the PPTP Client is connecting to the entire LAN subnet Subnet Mask Enter the subnet mask used on the remote network i e 255 255 255 0 Gateway IP Enter the WAN IP of the remote network i e 24 106 10 54 The last octet should not be zero in this case Enter the full WAN IP address Client Setting PPTP Client Check this box to enable the Barricade s PPTP Client Host Check this box on...

Page 47: ... the PPTP server s LAN is using an IP scheme of 192 168 2 xxx change the IP Pool to be 192 168 2 xxx 192 168 2 xxx Also make sure that this range does not conflict with the ranges of other DHCP servers in the network Figure 1 2 Then press the Apply button and your settings will be saved Figure 1 3 Step 8 Now click the Status link on the left navigation bar and you should see a Connect and Disconne...

Page 48: ...ngs previously configured in the VPN PPTP section Once the connection is established the information will be displayed on the STATUS page and in the SECURITY LOG as well Figure 1 5 Once you are connected you will be able to access the computers on the remote network as if they were on your local LAN ...

Page 49: ...X is equal to a number between 2 and 254 Step 1 Open up your web browser and type in the IP Address of your Barricade Plus Step 2 Enter your password to log into the router and then go into the Advanced Setup Step 3 Click on the link for VPN on the left Then click PPTP Step 4 The router allows you to configure up to 20 different PPTP VPN accounts Click the Edit link for the first account and then ...

Page 50: ...ast octet must always be zero because the PPTP Client is connecting to the entire LAN subnet Subnet Mask Enter the subnet mask used on the remote network i e 255 255 255 0 Gateway IP This value must be 0 0 0 0 when configuring the Barricade Plus as a PPTP Server Client Setting PPTP Client Leave this box unchecked when configuring a PPTP Server Host Check this box only if you will be using a Window...

Page 51: ... i e If the PPTP server s LAN is using an IP scheme of 192 168 5 xxx change the IP Pool to be 192 168 5 xxx 192 168 5 xxx Also make sure that this range does not conflict with the ranges of other DHCP servers in the network Figure 1 2 Then press the Apply button and your settings will be saved Figure 1 3 Step 8 Now click the Status link on the left navigation bar and you should see Disconnect butt...

Page 52: ...nd the Server will begin to terminate the PPTP VPN session Once the connection has been broken the information will be displayed on the STATUS page and in the SECURITY LOG as well The PPTP Server should show that the Line is Disconnected ...

Page 53: ...d type in the IP Address of your Barricade Plus Step 2 Enter your password to log into the router and then go into the Advanced Setup Step 3 Click on the link for VPN on the left Then click IPSec Step 4 The Barricade Plus supports a maximum of 3 IPSec tunnels These tunnels can be established to different gateways routers simultaneously For example Four companies in different physical locations cou...

Page 54: ...way is 192 168 3 1 type in 192 168 3 0 Subnet Mask Enter the subnet mask of the remote LAN Security Gateway Enter the exact WAN IP of the remote network This must be a public IP address such as 64 58 123 12 Hash Algorithm MD5 Message Digest 5 A one way hash algorithm that essentially verifies data integrity SHA1 Secure Hash Algorithm 1 A cryptographic message digest algorithm used to create digita...

Page 55: ...Figure 1 1 Tunnel 2 Figure 1 2 Tunnel 3 ...

Page 56: ...lus has a LAN IP of 192 168 2 1 and it has been configured to connect to three other Barricade Plus units Note that each of the remote Barricade Plus units have DIFFERENT LAN IP addresses This is essential to the successful establishment of the IPSec VPN ...

Page 57: ... home network DNS DNS stands for Domain Name System which allows Internet host computers to have a domain name such as www smc com and one or more IP addresses such as 192 34 45 8 A DNS server keeps a database of host computers and their respective domain names and IP addresses so that when a domain name is requested as in typing www smc com into your Internet browser the user is sent to the prope...

Page 58: ... peer to peer networks are often simpler to install and manage but dedicated servers provide better performance and can handle higher transaction volume Multiple servers are used in large networks The message transfer is managed by a transport protocol such as TCP IP and NetBEUI The physical transmission of data is performed by the access method Ethernet Token Ring etc which is implemented in the ...

Page 59: ... network layer protocol processing then sends the signals via an appropriate data link and physical layer protocols to another network SHA1 The Secure Hash Algorithm is a cryptographic message digest algorithm used to create digital signatures It is slower than MD5 but more secure SNMP Format used for network management data Data is passed between SNMP agents processes that monitor activity in hub...

Page 60: ...CP and UDP User Datagram Protocol are the two transport protocols in TCP IP TCP ensures that a message is sent accurately and in its entirety However for real time voice and video there is really no time or reason to correct errors and UDP is used instead UDP User Datagram Protocol This is a protocol within the TCP IP protocol suite that is used in place of TCP when a reliable delivery is not requ...

Page 61: ...machines as if it were actually on that local network ...

Reviews: