Page 52 - Configuration Examples
Task Description
Step 4
For IP Office
Location B
create an IPSec
tunnel (see The IP Security Menu on page 24).
Main tab:
Local Configuration:
•
Name = IPSec_Tunnel
•
IP Address = 192.168.43.0
•
IP Mask = 255.255.255.0
•
Tunnel Endpoint IP Address =
192.168.43.1
Remote Configuration:
•
IP Address = 192.168.42.0
•
IP Mask = 255.255.255.0
•
Tunnel Endpoint IP Address = 192.168.42.1
See notes in step 3 above.
The Local Tunnel Endpoint IP Address is the
near end tunnel endpoint. Hence, for
Location A, this will be 192.168.43.1, which
is the LAN1 IP address of Location B
The Remote Gateway is the far end tunnel
endpoint. Hence, for Location B, this will be
192.168.42.1, which is the LAN1 IP address
of Location A.
Step 5
For both IP Office Location A and Location B,
perform the following:
IKE Polices tab
•
Shared Secret = password
•
Exchange Type = ID port
•
Encryption = DES
•
Authentication = MD5
•
DH Group = Group 2
•
Life Type = Seconds
•
Life = 86400
These parameters set the Phase 1
negotiation for the SA.
Step 6
For both IP Office Location A and Location
B,perform the following:
IPSec Policies tab
•
Protocol = ESP
•
Encryption = DES
•
Authentication = MD5
•
Life Type = Seconds
•
Life = 86400
These parameters set the Phase 2
negotiation for the SA.
Step 7
Checking to see if the tunnel is up.
Use the SysMonitor application to check if
ESP packets are generated when ICMP ping
requests are sent between the subnets.
For VoIP configuration refer to Part 3 VoIP Configuration on page 53.
Page 52 - Configuration Examples
IP Office (R3.0)
Part 2: VPN configuration
40DHB0002UKER Issue 3 (4th February 2005)