
Technical Configuration Guide:
SOHO Secure RAS with VPN Gateway and VPN Router
V1.0 September, 2006
_______________________________________________________________________________________________________________________
7
External Distribution
NORTEL
deploy a single Nortel VPN Gateway provisioned with thousands of concurrent SSL and/or IPSec users to suit
their specific remote access requirements.
High Scalability and Performance
The VPN Gateways scales up to thousands of concurrent SSL and IPSec VPN user tunnels and provides
hundreds of Mbps of aggregate 3DES VPN throughput. Additional feature license keys can be purchased to
expand the VPN Gateway's user capacity and function with each VPN Gateway capable of server up to 255
unique domains. VPN Gateways can also be clustered in groups of up to 32 units. Adding a VPN Gateway to the
cluster is a simple plug-n-play procedure with the Single System Image (SSI) management capability.
Strong Remote Endpoint Security
The VPN Gateways provide a suite of safeguard features to protect against malicious intent and user negligence.
The VPN Gateway 3050/3070 supports the Nortel VPN Tunnel Guard feature which enforces endpoint security
checking for both client and client-less VPN endpoints. VPN Tunnel Guard enables the administrator to define
endpoint security policies on the VPN Gateway itself and ensure all remote users/devices connecting to that VPN
Gateway are inspected for compliance to a security policy, preventing end-user devices from becoming a vehicle
for viruses or other unwanted intrusions into the secure enterprise network through the VPN tunnel.
1.1.2 Nortel SOHO VPN Router
The VPN Router 200 series is an affordable all-in-one solution for tying small office and home office locations as
well as teleworkers into a secure corporate network.
The VPN Router 200 series of VPN devices (formerly known as Contivity) are the answer to enterprises requiring
low-cost secure connectivity across the Internet or managed IP networks. Designed for telecommuter and small
office/home offices, the VPN Router 200 series provides Virtual Private Networking (VPN), firewall, IP routing,
URL/content filtering and optional integrated DSL in a compact easy-to-manage platform. Consisting of the VPN
Router 221 and 251 models, the VPN Router 200 series provides options for small sites seeking secure Internet
connectivity along with firewall-based perimeter defense functions in a single device. Both models have an
integrated four-port Ethernet switch for connecting local LAN devices. The VPN Router 221 provides Ethernet-to-
Ethernet connectivity while the VPN Router 251 offers integrated ADSL conforming to international standards
allowing global deployment.
Figure 4: VPN Router 200 (VR200)
Low-cost IP Security for Small Sites
With its low-cost and integrated services, the VPN Router 200 is an affordable device for small sites that might
previously have felt such an IP security solution was too costly. It combines the advanced IP-VPN, firewall,