4-13
VPN 3002 Hardware Client Getting Started
OL-2854-01
Chapter 4 Using the Command-Line Interface for Quick Configuration
Configuring PAT or Network Extension mode
Step 7
The system prompts you to enter the user password. Minimum is 4, maximum is 32 characters,
case-sensitive. The system displays only asterisks.
> IPSec User Password
Quick -> _
Step 8
The system prompts you to reenter the user password.
Verify -> _
Configuring PAT or Network Extension mode
This section lets you configure this VPN 3002 to use either PAT or Network Extension mode. You have
this option only if you have changed the private interface IP address.
If you have not changed the private interface IP address, the system displays the following message:
NOTE:-- Because the IP Address of the Private Interface was not
NOTE:-- changed from the initial default value, you cannot disable
NOTE:-- PAT on the IPSec tunnel to the VPN Concentrator.
Client Mode (PAT)
Client mode, also called PAT (Port Address Translation) mode, isolates all devices on the private
network from those on the public network. In PAT mode:
•
IPSec encapsulates all traffic going from the private network of the VPN 3002 to the network(s)
behind the IKE peer, i.e., the central-site VPN Concentrator.
•
PAT includes NAT (Network Address Translation). NAT translates the network addresses of the
devices connected to the VPN 3002 private interface to the VPN Concentrator assigned IP address
on the public interface, and also keeps track of these mappings so that it can forward replies to the
correct device.
All traffic from the private network appears on the network behind the central-site VPN Concentrator
(the IKE peer) with a single source IP address. This IP address is the one the central-site VPN
Concentrator assigns to the VPN 3002. The IP addresses of the computers on the private network are
hidden. You cannot ping or access a device on the VPN 3002 private network from outside of the private
network, or directly from a device on the private network at the central site.
VPN 3000 Concentrator Settings Required for PAT
For the VPN 3002 to use PAT, follow these requirements for the central-site VPN Concentrator.
1.
The VPN Concentrator at the central site must be running Software version 3.0 or later.
2.
Address assignment must be enabled, by whatever method you choose to assign addresses (for
example, DHCP, address pools, per user, or client-specified). If the VPN Concentrator uses address
pools for address assignment, make sure to configure the address pools your network requires. See
Chapter 6, “Address Management,” in the VPN 3000 Series Concentrator Reference Volume 1:
Configuration.