Chapter 7
VPN
This Chapter describes the VPN capabilities and configuration required for
common situations.
7
Overview
This section describes the VPN (Virtual Private Network) support provided by your
Broadband VPN Router.
A VPN (Virtual Private Network) provides a secure connection between 2 points, over an
insecure network - typically the Internet. This secure connection is called a
VPN Tunnel
.
There are many standards and protocols for VPNs. The standard implemented in the
Broadband VPN Router is
IPSec
.
IPSec
IPSec is a near-ubiquitous VPN security standard, designed for use with TCP/IP networks. It
works at the packet level, and authenticates and encrypts all packets traveling over the VPN
Tunnel. Thus, it does not matter what applications are used on your PC. Any application can
use the VPN like any other network connection.
IPsec VPNs exchange information through logical connections called
SA
s (Security
Associations). An SA is simply a definition of the protocols, algorithms and keys used
between the two VPN devices (endpoints).
Each IPsec VPN has two SAs - one in each direction. If
IKE
(Internet Key Exchange) is used
to generate and exchange keys, there are also SA's for the IKE connection as well as the IPsec
connection.
There are two security modes possible with IPSec:
•
Transport Mode
- the payload (data) part of the packet is encapsulated through
encryption but the IP header remains in the clear (unchanged).
The Broadband VPN Router does NOT support Transport Mode.
•
Tunnel Mode
- everything is encapsulated, including the original IP header, and a new IP
header is generated. Only the new header in the clear (i.e. not protected) This system
provides enhanced security.
The Broadband VPN Router always uses Tunnel Mode.
IKE
IKE (Internet Key Exchange) is an optional, but widely used, component of IPsec. IKE
provides a method of negotiating and generating the keys and IDs required by IPSec. If using
IKE, only a single key is required to be provided during configuration. Also, IKE supports
using
Certificates
(provided by CAs - Certification Authorities) to authenticate the identify of
the remote user or gateway.
If IKE is NOT used, then all keys and IDs (SPIs) must be entered manually, and Certificates
can NOT be used. This is called a "Manual Key Exchange".
When using IKE, there are 2 phases to establishing the VPN tunnel:
64
Содержание ALL1294VPN
Страница 1: ...Broadband VPN Router ALL1294VPN Broadband Internet Access 4 Port Switching Hub User s Guide ...
Страница 28: ...PC Configuration Figure 16 Windows NT4 0 DNS 25 ...
Страница 59: ...Broadband VPN Gateway User Guide request was blocked Destination The destination URL or IP address 56 ...