Configure Virtual Private Networking (VPN)
IPsec parameters
Digi TransPort WR Routers User Guide
425
Logic flow for VPN Concentrator acting as a responder to a session initiated from the remote
site
1
When a remote site needs to create an IPsec SA with the VPN Concentrator it sends an IKE
request to the VPN Concentrator.
2
The VPN Concentrator needs to be able to confirm that the remote device is authorized to create
an IPsec tunnel. The remote site supplies its ID to the host during the IKE negotiations. The VPN
Concentrator uses this ID in a search of the IPsec tunnels configured and dynamic IPsec tunnels
to see if the supplied ID matches the configured Peer ID (
peerid
). If a match is found, the MYSQL
database is queried to retrieve the information required to complete the negotiation (such as
pre-shared key/password). If no matching base IPsec tunnel is found, router uses the local user
configuration to locate the password, and a normally configured IPsec tunnel must also exist.
3
Once the information is retrieved from the MySQL database, IKE negotiations continue, and the
created IPsec SAs will be associated with the dynamic IPsec tunnel.
4
As long as the dynamic IPsec tunnel exists, it behaves just like a normal IPsec tunnel. such as SAs
being replaced/removed as required.
5
If errors are received from the MySQL database, or not enough fields are returned, the dynamic
IPsec tunnel is removed, and IKE negotiations in progress are terminated.
6
There are a limited number of dynamic IPsec tunnels. If the number of free dynamic IPsec tunnel
is less than
10
percent of the total number of dynamic IPsec tunnel, the router periodically
removes the oldest dynamic IPsec tunnel. This is done to ensure that there will always be some
free dynamic IPsec tunnel available for incoming connections from remote routers. To view the
current dynamic tunnels that exist using the WEB server, browse to
Management >
Connections > Virtual Private Networking (VPN) > IPsec
. The table indicates the base IPsec
tunnel and the
Remote Peer ID
in the status display, to help identify which remote sites are
currently connected.
Содержание TransPort WR11
Страница 1: ...User Guide Digi TransPort WR Routers ...
Страница 215: ...Configure network interfaces Configure mobile cellular interfaces Digi TransPort WR Routers User Guide 215 ...
Страница 650: ...Configure system settings NTP parameters Digi TransPort WR Routers User Guide 650 ...
Страница 661: ...Configure system settings General system parameters Digi TransPort WR Routers User Guide 661 ...
Страница 662: ...Configure system settings General system parameters Digi TransPort WR Routers User Guide 662 ...
Страница 663: ...Configure system settings General system parameters Digi TransPort WR Routers User Guide 663 ...
Страница 682: ...Configure Remote Management SNMP parameters Digi TransPort WR Routers User Guide 679 ...
Страница 683: ...Configure Remote Management SNMP parameters Digi TransPort WR Routers User Guide 680 ...
Страница 813: ...Manage networks and connections Top Talkers Digi TransPort WR Routers User Guide 808 ...
Страница 814: ...Manage networks and connections Top Talkers Digi TransPort WR Routers User Guide 809 ...
Страница 815: ...Manage networks and connections Top Talkers Digi TransPort WR Routers User Guide 810 ...
Страница 816: ...Manage networks and connections Top Talkers Digi TransPort WR Routers User Guide 811 ...
Страница 817: ...Manage networks and connections Top Talkers Digi TransPort WR Routers User Guide 812 ...
Страница 818: ...Manage networks and connections Top Talkers Digi TransPort WR Routers User Guide 813 ...
Страница 855: ...Device administration Reboot the router Digi TransPort WR Routers User Guide 844 ...