3.4.7. PPTP Client
Fig. 65. PPTP and Virtual Second LAN.
By PPTP and Virtual Second LAN, a WISP can securely manage access points behind the access
gateway that acts as an NAT server.
As illustrated in Fig. 65, the access gateway exposes two LAN-side private networks—one is for the
wireless clients (
Physical First LAN
: 192.168.0.xxx) and the other is for the access points (
Virtual
Second LAN
: 10.0.0.xxx). The two private networks are separated so that now traffic is allowed be-
tween the two private networks. This way, a hacker on the 192.168.0.xxx network cannot attack ac-
cess points on the 10.0.0.xxx network.
After the PPTP client of the access gateway establishes a PPTP tunnel with a remote PPTP server (i.e.,
210.22.11.1), a
static route
between the PPTP tunnel (10.0.1.11) and the virtual second LAN (10.0.0.1)
is created. Thereafter, any host (ex., 10.0.1.5) on the remote 10.0.1.xxx network can reach the access
points on the 10.0.0.xxx network for access point management purposes. And all management packets
are encrypted when transmitted in the PPTP tunnel.
TIP:
Alternatively, you can use an NAT port mapping-based way for behind-NAT access point man-
agement. See Section 3.7.4 for more information.
48
Содержание IWE1200A-G
Страница 1: ...USER S MANUAL...
Страница 14: ...7...
Страница 72: ...Fig 95 Advertisement links settings Fig 96 Advertisement links in action 65...