246
MDS Orbit MCR/ECR Technical Manual
MDS 05-6632A01, Rev. F
2.
Site-to-Site GRE/IPsec L3VPN
–
This enables
routing
of traffic to/from one or more local LANs of
Orbit from/to one or more remote LANs on the other side of the Remote IPsec router through a
single GRE tunnel protected by transport mode IPsec connection.
Orbit
Remote IPsec
Gateway/Router
Local LAN#1
192.168.1.0/24
Remote LAN#1
192.168.3.0/24
Customer
Network/
Internet
Cellular
network
GRE tunnel protected by transport-
mode IPsec connection carrying traffic
between local and remote LANs
In this setup, there are one or more LANs behind Orbit and traffic from these LANs needs to be
routed
towards a one or more remote LANs on the other side of the remote router through a
GRE tunnel protected by IPsec transport mode connection. The routes are added for remote LAN
networks on Orbit either statically (via manual configuration) or dynamically (by running routing
protocols like RIP/OSPF/BGP over GRE tunnel).
Local LAN#2
192.168.2.0/24
Remote LAN#2
192.168.4.0/24
3.
Site-to-Site GRE/IPsec L2VPN
–
This enables
bridging
of traffic to/from one or more local LANs of
Orbit from/to one or more remote LANs on the other side of the Remote IPsec router through a
single GRE tunnel protected by transport mode IPsec connection. Orbit also supports VLAN trunking
over GRE tunnel for a case where there is more than one LAN behind Orbit and remote router.
Orbit
Remote IPsec
Gateway/Router
Local LAN
192.168.1.0/24
Remote LAN
192.168.1.0/24
Customer
Network/
Internet
Cellular
network
GRE tunnel protected by transport-
mode IPsec connection carrying traffic
between local and remote LANs
In this setup, there is single LAN behind Orbit and traffic from this LAN needs to be
bridged
with
single remote LAN on the other side of the remote router through a GRE tunnel protected by
IPsec transport mode connection. In this mode, the GRE tunnel is in Ethernet-over-GRE mode and
simulates a point-to-point layer-2 VPN enabling MAC visibility and learning between the two
sites. Orbit also supports VLAN trunking over the GRE tunnel in a case there is more than one
LAN behind Orbit and Remote router.
4.
Dynamic Multipoint/Mesh VPN (DMVPN)
-
DMVPN combines multipoint GRE (mGRE) Tunnels,
IPSec encryption and NHRP (Next Hop Resolution Protocol) functionality to enable easier
configuration of hub-to-spoke VPN deployments. In addition, it enables formation of on-demand
dynamic tunnels between spokes for a full or partial mesh VPN network. The routes are added for
Содержание MDS ORBIT ECR
Страница 15: ...MDS 05 6632A01 Rev F MDS Orbit MCR ECR Technical Manual 15 ...
Страница 35: ...MDS 05 6632A01 Rev F MDS Orbit MCR ECR Technical Manual 35 ...
Страница 145: ...MDS 05 6632A01 Rev F MDS Orbit MCR ECR Technical Manual 145 ...
Страница 188: ...188 MDS Orbit MCR ECR Technical Manual MDS 05 6632A01 Rev F ...
Страница 302: ...302 MDS Orbit MCR ECR Technical Manual MDS 05 6632A01 Rev F Figure 3 224 SNMP Main Page ...
Страница 380: ...380 MDS Orbit MCR ECR Technical Manual MDS 05 6632A01 Rev F ...
Страница 389: ...MDS 05 6632A01 Rev F MDS Orbit MCR ECR Technical Manual 389 ...
Страница 393: ...MDS 05 6632A01 Rev F MDS Orbit MCR ECR Technical Manual 393 ...
Страница 407: ...MDS 05 6632A01 Rev F MDS Orbit MCR ECR Technical Manual 407 ...
Страница 449: ...MDS 05 6632A01 Rev F MDS Orbit MCR ECR Technical Manual 449 ...
Страница 451: ...MDS 05 6632A01 Rev F MDS Orbit MCR ECR Technical Manual 451 ...
Страница 452: ...452 MDS Orbit MCR ECR Technical Manual MDS 05 6632A01 Rev F ...
Страница 453: ...MDS 05 6632A01 Rev F MDS Orbit MCR ECR Technical Manual 453 ...
Страница 459: ...MDS 05 6632A01 Rev F MDS Orbit MCR ECR Technical Manual 459 NOTES ...
Страница 460: ...460 MDS Orbit MCR ECR Technical Manual MDS 05 6632A01 Rev F ...
Страница 461: ......
Страница 463: ...GE MDS LLC Rochester NY 14620 Telephone 1 585 242 9600 FAX 1 585 242 9620 www gemds com 175 Science Parkway ...