3-16
VPN 3002 Hardware Client Getting Started
OL-2854-01
Chapter 3 Using the VPN 3002 Hardware Client Manager for Quick Configuration
Configuring PAT or Network Extension Mode
2.
Configure a group to which you assign this VPN 3002. This includes assigning a
group name and
password. Refer to the chapter, “User Management,” in the VPN 3000 Series Concentrator
Reference Volume 1: Configuration.
3.
Configure one or more users for the group, including usernames and passwords.
4.
Configure either a default gateway or a static route to the VPN 3002 private network. Refer to the
chapter, “IP Routing,” in the VPN 3000 Series Concentrator Reference Volume 1: Configuration.
5.
If you want the VPN 3002 to be able to reach devices on other networks that connect to the VPN
Concentrator, review your Network Lists. Refer to the chapter, “Policy Management,” in the VPN
3000 Series Concentrator Reference Volume 1: Configuration.
Tunnel Initiation
The VPN 3002 always initiates the tunnel to the central-site VPN Concentrator. The central-site VPN
Concentrator cannot initiate a tunnel to a VPN 3002. The VPN 3002 creates only one IPSec tunnel to
the central-site VPN Concentrator, in either PAT or Network Extension mode. The tunnel can support
multiple encrypted data streams between users behind the VPN 3002 and the central site. With split
tunneling enabled, it can also support multiple unencrypted data streams to the internet.
In PAT mode, the tunnel establishes when data passes to the VPN Concentrator, or when you click
Connect Now in the Monitoring | System Status screen.
In Network Extension mode, the VPN 3002 automatically attempts to establish a tunnel to the VPN
Concentrator.
Tunnel Initiation with Interactive Unit Authentication
In either Client or Network Extension mode, when you enable interactive unit authentication, the tunnel
establishes when you perform the following steps.
Step 1
In the VPN 3002 Hardware Client login screen, click the Connection/Login Status button. The
Connection/Login screen displays.
Step 2
Click Connect Now.
Step 3
Enter the username and password for the VPN 3002.
Refer to the section, “Logging in With Interactive Unit and Individual User Authentication,” in
Chapter 1 of the VPN 3002 Hardware Client Reference for detailed instructions.
Alternatively, you can click Connect Now on the in the Monitoring | System Status screen, after which
the system prompts you to enter the username and password for the VPN 3002. Refer to the section,
Monitoring | System Status in the “Monitoring” chapter of the VPN 3002 Hardware Client Reference for
detailed instructions.
Data Initiation
After the tunnel is established between the VPN 3002 and the central-site VPN Concentrator, the VPN
Concentrator can initiate data exchange only in Network Extension mode with all traffic travelling
through the tunnel. If you want the tunnel to remain up indefinitely, you should configure the VPN 3002
for Network Extension mode and not use split tunneling.