IPSec
769
Programming Operations Guide
Networks would have two networks configured as 10.10.10.0 with a mask 255.255.255.0 and
10.10.11.0 with a mask 255.255.255.0 and the Remote Accessible Networks would be 12.12.12.0
with a mask of 255.255.255.0. All packets that do not match these rules will be NATed and sent
out the interface and not through the tunnel. This is a useful configuration if access to both the
Internet and the other side of an IPSec tunnel is desired.
Dialup ISDN connections
When you are creating an IPSec tunnel over a Dialup ISDN connection, the endpoint must have a
fixed IP address.
Compatibility with Contivity Extranet Switch and Shasta 5000
When connecting to a Contivity Extranet Switch, you must disable Vendor ID and Compression
under Base Class on the Contivity Extranet Switch.
Business Communications Manager does not support the IPSec RIP implementation used by the
Contivity Extranet Switch. Use Static Routes when connecting to the Contivity Extranet Switch.
When connecting to a Shasta 5000, you must set the PFS to No on the Tunnel configuration of
Business Communications Manager.
IPSec and PPTP
The Remote Accessible Networks of an IPSec tunnel cannot be the same as a Destination Network
on a PPTP tunnel. The Remote Endpoint of an IPSec tunnel’s Remote Endpoint cannot be the
same as a Destination Endpoint on a PPTP tunnel.
Multiple IP Address restrictions
Although the Business Communications Manager supports the configuration of additional IP
addresses on its network interfaces, IPSec does not currently support the use of these additional IP
addresses for Branch Office Local Endpoint Addresses, Remote Endpoint Addresses or the
Destination IP Address for IPSec VPN Clients.
For more information about Multiple IP addresses, refer to
“Configuring multiple IP addresses for
the LAN interface” on page 671
.
Firewall rules for IPSec Branch Office and Remote User Tunnels
In order to allow IPSec packets through the firewall interface which blocks all incoming packets, a
number of rules must be configured. In addition to allowing the IPSec packets through, you must
also remember to create rules to allow the packets that come through the tunnel.
In the Branch office case, up to three rules must be created. One is for the key exchange protocol
(IKE), the other two are for the type of protocol used (ESP and/or AH).
Table 226
,
Table 227
and
Table 228
show the rules required (these are all inbound rules).
Содержание BCM 3.7
Страница 1: ...Part No N0008589 3 3 December 2006 Business Communications Manager 3 7 Programming Operations Guide...
Страница 4: ...4 Software licensing N0008589 3 3...
Страница 32: ...32 Contents N0008589 3 3 W 937 Index 939...
Страница 46: ...46 Tables N0008589 3 3...
Страница 64: ...64 How to get help N0008589 3 3...
Страница 90: ...90 Manually activating Telnet N0008589 3 3...
Страница 116: ...116 Delayed system restart N0008589 3 3...
Страница 194: ...194 Configuring a data module N0008589 3 3...
Страница 276: ...276 Setting line telco features N0008589 3 3...
Страница 310: ...310 Using COS passwords N0008589 3 3...
Страница 364: ...364 Enhanced 911 E911 configuration N0008589 3 3...
Страница 380: ...380 Renumbering DNs N0008589 3 3...
Страница 398: ...398 Saving wizard pages on your computer N0008589 3 3...
Страница 458: ...458 Voice Mail settings N0008589 3 3...
Страница 488: ...488 Setting system telco features N0008589 3 3...
Страница 508: ...508 Other programming that affects public networking N0008589 3 3...
Страница 522: ...522 PRI networking using Call by Call services N0008589 3 3...
Страница 592: ...592 Monitoring Hunt groups N0008589 3 3...
Страница 636: ...636 Configuring Double Density N0008589 3 3...
Страница 640: ...640 Using the Network Update Wizard N0008589 3 3...
Страница 666: ...666 Importing and Exporting DHCP data N0008589 3 3...
Страница 722: ...722 Restarting the router N0008589 3 3...
Страница 726: ...726 Important Web Cache considerations N0008589 3 3...
Страница 748: ...748 Configuring an Interface with NAT N0008589 3 3...
Страница 794: ...794 IPSec N0008589 3 3...
Страница 818: ...818 Configuring the Policy Agent characteristics N0008589 3 3...
Страница 832: ...832 Firewall rules for Business Communications Manager with Dialup interfaces N0008589 3 3...
Страница 876: ...876 ISDN Programming N0008589 3 3...
Страница 1004: ...1004 Index N0008589 3 3...