Chapter 6 IP security and VPN
193
Using the BayStack Instant Internet Management Software Version 7.11
Example for configuring the non-Contivity client connection on the
CES
This procedure provides an example for configuring a non-Contivity client
connection on the CES for tunneling. For detailed information, refer to your
product documentation.
To configure the non-Contivity client connection on the CES:
1
From Profiles > Networks, add a network that will be using the VPN.
2
From Profiles > Groups, add a group or select an existing group that will be
using the VPN and edit that group with the following information.
•
For Connectivity, configure the idle timeout to 1 be minute and then click
OK.
•
For IPsec, select the network that was added in step 1 in the Split Tunnel
Networks box.
•
For IPsec, configure the CES to allow non-Contivity clients for the
appropriate group and then click OK.
3
From Profiles > Users, add a user or select an existing user from the group
that was edited in step 2 to use the VPN.
You must create the user as a “local user” in the LDAP database (internal or
external); you cannot use RADIUS authentication for this type of connection.
4
Edit the new or selected user with the following information:
•
Assign an address to the client user.
This address must be usable on Contivity’s private network, but there are
no restrictions in terms of whether the address is public, private, or even a
native part of Contivity’s private network. This address should be the
same as the Static address in the Instant Internet setup. Do not add a
subnet mask.
•
Assign a user ID and password.
The user ID and password must match the one given on the other end of
the tunnel.
5
Ensure that another router on Contivity’s private network has a static route for
the client address, with a destination of Contivity’s private address or use
proxy ARP.
Содержание 400
Страница 16: ...16 Contents 300868 G ...
Страница 22: ...22 Figures 300868 G ...
Страница 24: ...24 Tables 300868 G ...
Страница 92: ...92 Chapter 2 User access administration 300868 G ...
Страница 114: ...114 Chapter 3 Internet activity logging 300868 G ...
Страница 166: ...166 Chapter 5 Advanced IP configuration 300868 G ...
Страница 200: ...200 Chapter 6 IP security and VPN 300868 G ...
Страница 256: ...256 Chapter 8 Advanced communications configuration 300868 G ...
Страница 302: ...302 Chapter 10 Instant Internet unit configuration support and diagnostics 300868 G ...
Страница 314: ...314 Appendix A Troubleshooting and error messages 300868 G ...
Страница 344: ......