MDS 05-6628A01, Rev. B
MDS Orbit MCR-4G Technical Manual
51
VPN
Understanding
The MCR supports standards-based IPsec Virtual Private Network (VPN) technology to securely connect
remote private network (LAN or WiFi) with the customer’s backoffice/data center private network see
Figure 23
). This allows IP traffic from/to devices connected to either LAN, WiFi or Serial port of the MCR
to securely flow to/from back-office applications via a secure tunnel through a public cellular network. The
tunneled application traffic is authenticated and encrypted to protect from eavesdropping, tampering and
replay attacks.
Invisible place holder
Figure 23. VPN Setup Example
Figure 23
shows an example network, where a remote Ethernet device is connected to MCR via Ethernet on
192.168.1.0/24 network. The MCR establishes a VPN connection with IPsec VPN gateway, thereby
securely connecting remote private network (192.168.1.0/24) with back-office private network
(192.168.2.0/24). This allows PC (192.168.2.2) to communicate with remote Ethernet device (192.168.1.2)
using any TCP/UDP/IP based protocol and vice versa.
IPsec, Internet Protocol Security, is a set of protocols defined by the IETF, Internet Engineering Task Force,
to provide IP security at the network layer.
An IPsec based VPN is made up by two parts:
• Internet Key Exchange protocol (IKE)
• IPsec protocols (ESP, AH)
The first part, IKE, is the initial negotiation phase, where the MCR and VPN gateway agree on which
methods will be used to provide security for the underlying IP traffic. There are two IKE protocol versions:
IKE-v1 and IKE-v2. These are not compatible with each other. The IKE-v2 is more efficient and therefore
should be preferred for new deployments. The MCR supports IKE-v1 and IKE-v2.
The other part is the actual IP data being transferred, using the encryption and authentication methods
agreed upon in the IKE negotiation. This is accomplished by using IPsec protocols like Encapsulating Secu-
rity Payload (ESP) or Authentication Header (AH). The MCR only supports ESP protocol as it provides
both encryption and authentication of the data. The AH protocol provides only data authentication.
Содержание Orbit MCR-4G
Страница 144: ...136 MDS Orbit MCR 4G Technical Manual MDS 05 6628A01 Rev B NOTES...
Страница 145: ...MDS 05 6628A01 Rev B MDS Orbit MCR 4G Technical Manual 137 NOTES...
Страница 146: ...138 MDS Orbit MCR 4G Technical Manual MDS 05 6628A01 Rev B...
Страница 148: ...GE MDS LLC Rochester NY 14620 Telephone 1 585 242 9600 FAX 1 585 242 9620 www gemds com 175 Science Parkway...