3-14
VPN 3002 Hardware Client Getting Started
OL-2854-01
Chapter 3 Using the VPN 3002 Hardware Client Manager for Quick Configuration
Configuring PAT or Network Extension Mode
•
PAT mode employs NAT (Network Address Translation). NAT translates the network addresses of
the devices connected to the VPN 3002 private interface to the IP address of the VPN 3002 public
interface. The central-site VPN Concentrator assigns this address. NAT also keeps track of these
mappings so that it can forward replies to the correct device.
All traffic from the private network appears on the network behind the central-site VPN Concentrator
(the IKE peer) with a single source IP address. This IP address is the one the central-site VPN
Concentrator assigns to the VPN 3002. The IP addresses of the computers on the VPN 3002 private
network are hidden. You cannot ping or access a device on the VPN 3002 private network from outside
of that private network, or directly from a device on the private network at the central site.
Client Mode with Split Tunneling
You assign the VPN 3002 to a client group on the central-site VPN Concentrator. If you enable split
tunneling for that group, IPSec and PAT are applied to all traffic that travels through the VPN 3002 to
networks within the network list for that group behind the central-site VPN Concentrator.
Traffic from the VPN 3002 to any destination other than those within the network list for that group on
the central-site VPN Concentrator travels in the clear without applying IPSec. NAT translates the
network addresses of the devices connected to the VPN 3002 private interface to the assigned IP address
of the public interface and also keeps track of these mappings so that it can forward replies to the correct
device.
The network and addresses on the private side of the VPN 3002 are hidden, and cannot be accessed
directly.
VPN Concentrator Settings Required for PAT
For the VPN 3002 to use PAT, you must meet these requirements for the central-site VPN Concentrator.
1.
The VPN Concentrator at the central site must be running Software version 3.x or later.
2.
Address assignment must be enabled, by whatever method you choose to assign addresses (the
options are DHCP, address pools, per user, or client-specified). If the central-site VPN Concentrator
uses address pools for address assignment, make sure to configure the address pools your network
requires. Refer to the chapter, “Address Management,” in the VPN 3000 Series Concentrator
Reference Volume 1: Configuration.
3.
Configure a group to which you assign this VPN 3002. This includes assigning a group name and
password. Refer to the chapter, “User Management,” in the VPN 3000 Series Concentrator
Reference Volume 1: Configuration.
4.
Configure one or more users for the group, including usernames and passwords.
Network Extension Mode
Network Extension mode allows the VPN 3002 to present a single, routable network to the remote
private network over the VPN tunnel. IPSec encapsulates all traffic from the VPN 3002 private network
to networks behind the central-site VPN Concentrator. PAT does not apply. Therefore, devices behind
the VPN Concentrator have direct access to devices on the VPN 3002 private network over the tunnel,
and only over the tunnel, and vice versa. The VPN 3002 must initiate the tunnel, but after the tunnel is
up, either side can initiate data exchange.