Prestige 662HW Series User’s Guide
VPN Screens
16-5
When there is outbound traffic with no inbound traffic, the Prestige automatically drops the tunnel
after two minutes.
16.7 NAT Traversal
NAT traversal allows you to set up a VPN connection when there are NAT routers between the two
IPSec routers.
Figure 16-3 NAT Router Between IPSec Routers
Normally you cannot set up a VPN connection with a NAT router between the two IPSec routers
because the NAT router changes the header of the IPSec packet. In the previous figure, IPSec router A
sends an IPSec packet in an attempt to initiate a VPN. The NAT router changes the IPSec packet’s
header so it does not match the header for which IPSec router B is checking. Therefore, IPSec router B
does not respond and the VPN connection cannot be built.
NAT traversal solves the problem by adding a UDP port 500 header to the IPSec packet. The NAT
router forwards the IPSec packet with the UDP port 500 header unchanged. IPSec router B checks the
UDP port 500 header and responds. IPSec routers A and B build a VPN connection.
16.7.1 NAT Traversal Configuration
For NAT traversal to work you must:
Use ESP security protocol (in either transport or tunnel mode).
Use IKE keying mode.
Enable NAT traversal on both IPSec endpoints.
In order for IPSec router A (see the figure) to receive an initiating IPSec packet from IPSec router B,
set the NAT router to forward UDP port 500 to IPSec router A.
16.7.2 Remote DNS Server
In cases where you want to use domain names to access Intranet servers on a remote network that has
a DNS server, you must identify that DNS server. You cannot use DNS servers on the LAN or from
the ISP since these DNS servers cannot resolve domain names to private IP addresses on the remote
network
The following figure depicts an example where three VPN tunnels are created from Prestige A; one to
branch office 2, one to branch office 3 and another to headquarters. In order to access computers that
use private domain names on the headquarters (HQ) network, the Prestige at branch office 1 uses the
Intranet DNS server in headquarters. The DNS server feature for VPN does not work with Windows
2000 or Windows XP.
Summary of Contents for Prestige 662HW Series
Page 26: ......
Page 28: ......
Page 36: ......
Page 54: ......
Page 56: ......
Page 64: ......
Page 84: ......
Page 100: ......
Page 116: ......
Page 128: ......
Page 150: ......
Page 154: ......
Page 162: ......
Page 168: ......
Page 194: ......
Page 196: ......
Page 200: ......
Page 208: ......
Page 214: ......
Page 216: ......
Page 230: ......
Page 242: ......
Page 244: ......
Page 252: ......
Page 258: ......
Page 262: ......
Page 266: ......
Page 272: ......
Page 286: ......
Page 290: ......
Page 310: ......
Page 328: ......
Page 352: ......
Page 358: ......
Page 362: ......
Page 374: ......
Page 376: ......
Page 394: ......
Page 398: ......
Page 400: ......
Page 410: ......
Page 444: ......
Page 452: ......