3-15
VPN 3002 Hardware Client Getting Started
OL-2854-01
Chapter 3 Using the VPN 3002 Hardware Client Manager for Quick Configuration
Configuring PAT or Network Extension Mode
In this mode, the central-site VPN Concentrator does not assign an IP address for tunneled traffic (as it
does in Client/PAT mode). The tunnel is terminated with the VPN 3002 private IP address (the assigned
IP address). To use Network Extension mode, you must configure an IP address other than the default of
192.168.10.1 and disable PAT.
In Network Extension mode, the VPN 3002 automatically attempts to establish a tunnel to the VPN
Concentrator. However, if you enable interactive unit authentication in either Client or Network
Extension mode, the tunnel establishes when you perform the following steps.
Step 1
Click the Connection/Login Status button on the VPN 3002 Hardware Client login screen. The
Connection/Login screen displays.
Step 2
Click Connect Now in the Connection/Login screen.
Step 3
Enter the username and password for the VPN 3002.
Alternatively, you can initiate a tunnel by clicking Connect Now on the in the Monitoring | System
Status screen.
Network Extension Mode per Group
VPN Concentrator software versions 3.6 and later let a network administrator restrict the use of network
extension mode. On the VPN Concentrator, you enable network extension mode for VPN 3002 hardware
clients on a group basis.
Note
If you disallow network extension mode, which is the default setting on the VPN Concentrator, the
VPN 3002 can connect to that VPN Concentrator in PAT mode only. In this case, be careful that all
VPN 3002s in the group are configured for PAT mode. If a VPN 3002 is configured to use network
extension mode and the VPN Concentrator to which it connects disallows network extension mode,
the VPN 3002 will attempt to connect every 4 seconds, and every attempt will be rejected; this is the
equivalent of denial of service attack.
Network Extension Mode with Split Tunneling
You always assign the VPN 3002 to a client group on the central-site VPN Concentrator. If you enable
split tunneling for that group, IPSec operates on all traffic that travels through the VPN 3002 to networks
within the network list for that group behind the central-site VPN Concentrator. PAT does not apply.
Traffic from the VPN 3002 to any other destination than those within the network list on the central-site
VPN Concentrator travels in the clear without applying IPSec. NAT translates the network addresses of
the devices on the VPN 3002 private network to the address of the VPN 3002 public interface. Thus the
network and addresses on the private side of the VPN 3002 are accessible over the tunnel, but are
protected from the Internet, that is, they cannot be accessed directly.
VPN Concentrator Settings Required for Network Extension Mode
For the VPN 3002 to use Network Extension mode, you must meet these requirements for the central-site
VPN Concentrator.
1.
The VPN Concentrator at the central site must be running Software version 3.x or later.