Configuration Examples - Page 47
Part 2 - IP Office Configuration
Task Description
Step 1
Within Manager, create and configure a
Logical LAN interface using the details
below (see page 33).
•
Name = Logical_LAN
•
IP Address = 217.37.69.116
•
IP Mask = 255.255.255.248
•
Gateway IP Address = 217.37.69.118
•
Gateway MAC Address (Internet Router)
•
Firewall Profile = none.
See Basic Internet access section - Internet
Access using a Logical Interface on page 34.
Note:
It is not necessary to specifically use a
Logical LAN. Alternatively, a LAN2
interface can be used (IP412 or SOE).
Step 2
Add an IP Route on IP Office:
•
IP Address
= <un-configured>
•
IP Mask
= <un-configured>
•
Gateway =
<un-configured>
•
Destination =
Logical_LAN
Step 3
Install the IPSec Licence.
Licence name – IPSec Tunneling.
An IPSec licence is required per IP Office.
Make sure the IPSec licence is valid in the
Manager.
Step 4
For IP Office create an IPSec tunnel:
Main tab
•
Name = IPSec_Tunnel
•
Local IP Address = 192.168.43.0
•
Local IP Mask = 255.255.255.0
•
Tunnel Endpoint
IP Address = <LocalInterface>
•
Remote IP Address = <unconfigured>
•
Remote IP Mask = <unconfigured>
•
Tunnel Endpoint
IP Address = <unconfigured>
A discrete name for the IPSec tunnel is
required.
The Local IP Address/Mask is the range of IP
addresses you want to secure through the
tunnel, e.g. 192.168.50.1/24 will give a subnet
address of 192.168.50.0.
This single IPSec configuration supports all
remote dial-up clients.
In the case where the remote endpoint is
unknown, the Remote IP Address, IP Mask and
Tunnel Endpoint IP Address should be left
<unconfigured>.
Step 5
For IP Office, perform the following on the
IKE Polices tab:
•
Shared Secret = password
•
Exchange Type = ID port
•
Encryption = DES
•
Authentication = MD5
•
DH Group = Group 1
•
Life Type = Seconds
•
Life = 86400
Both tunnel endpoints must have the same-
shared secret.
Encryption set to DES.
Authentication set to MD5
Diffie-Hellman Group = Group 2
This is the time period before a new key is
generated (86400 represents one day in
seconds).
IP Office (R3.0) Virtual Private Networking
Configuration Examples - Page 47
40DHB0002UKER Issue 3 (4th February 2005)
Part 2: VPN configuration