Typical installations
Issue 5 June 2008
587
Configuring the mesh VPN topology
1. Configure Branch Office 1 as follows:
●
The default gateway is the Internet interface
●
VPN policy is configured on the Internet interface egress as follows:
●
Traffic from the local subnets to the second spoke subnets -> encrypt, using tunnel
mode IPSec, with the remote peer being the second spoke
●
Traffic from the local subnets to any IP address -> encrypt, using tunnel mode
IPSec, with the remote peer being the main office (VPN hub)
●
An access control list (ACL) is configured on the Internet interface to allow only the
VPN / ICMP traffic. See
Table 140
for configuration settings.
Note:
Note:
For information about using access control lists, see
Configuring policy
on
page 637.
Table 140: Configuring the mesh VPN topology – Branch Office 1
Traffic
direction
ACL parameter
ACL
value
Description
Ingress
IKE from Main Office IP to
Branch IP
Permit
-
Ingress
ESP from Main Office IP
to Branch IP
Permit
-
Ingress
IKE from Second Branch
IP to Branch IP
Permit
-
Ingress
ESP from Second Branch
IP to Branch IP
Permit
-
Ingress
ICMP from any IP address
to local tunnel endpoint
Permit
This enables the PMTUD
application to work
Ingress
All allowed services from
any IP address to any
local subnet
Permit
Due to the definition of the VPN
Policy, this will be allowed only if
traffic comes over ESP
Ingress
Default
Deny
-
Egress
IKE from Branch IP to
Main Office IP
Permit
-
Egress
ESP from Branch IP to
Main Office IP
Permit
-
1 of 2
Содержание Media Gateway G250
Страница 1: ...Administration for the Avaya G250 and Avaya G350 Media Gateways 03 300436 Issue 5 June 2008 ...
Страница 24: ...Contents 24 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 32: ...Introduction 32 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 38: ...Configuration overview 38 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 128: ...Basic device configuration 128 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 210: ...Configuring Standard Local Survivability SLS 210 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 244: ...Configuring logging 244 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 258: ...Configuring VoIP QoS 258 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 354: ...Configuring Emergency Transfer Relay ETR 354 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 370: ...Configuring SNMP 370 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 402: ...Configuring advanced switching 402 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 486: ...Configuring monitoring applications 486 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 548: ...Configuring the router 548 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 664: ...Configuring policy 664 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 682: ...Configuring policy based routing 682 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 686: ...Setting synchronization 686 Administration for the Avaya G250 and Avaya G350 Media Gateways ...