786
IPSec
N0008589 3.3
Split Tunneling security considerations
Business Communications Manager takes precautions against violators potentially hacking
tunneled information when the Business Communications Manager is operating in Split Tunnel
mode.
The primary precaution is to drop packets that do not have the IP address that is assigned to the
tunnel connection as its source address. For example, if you have a PPP dial-up connection to the
Internet with an IP address of 192.168.21.3, and you set up an IPSec client connection to a
Business Communications Manager and you are assigned an IPSec client IP address of
192.192.192.192, then any packets that attempt to pass through the IPSec client tunnel connection
with a source IP address of 192.168.21.3 (or any address other than 192.192.192.192) will be
dropped.
To completely eliminate security risks, you should not use the Split Tunneling feature.
Adding a Remote User IPSec Tunnel
A Remote User IPSec Tunnel connects a remote computer to the Business Communications
Manager system.
Assigning an IP Address to a Remote User Account
The Remote User account requires that an IP address is assigned to the Remote User when they log
into the Business Communications Manager. This IP address must be in the private IP network
that the Remote User is able to access.
The Business Communications Manager supports two methods of assigning an IP Address to the
Remote User Account. You can use a static IP address or a dynamic IP address from an IP Address
Pool.
Static IP Address
To assign a static IP address to the Remote User account, you must configure the following two
options when you configure the Remote User Account settings:
•
Static IP Address
•
Static Subnet Mask
Note:
The remote computer must have version 4.60 of the Contivity VPN Client
installed.
Note:
If the computer running the VPN client is not on the same subnet as the Destination
address (i.e. there is at least one router between the computer and the Business
Communications Manager), then the default Next Hop Router on the Business
Communications Manager must also be through this interface. For instructions on setting
up a default Next Hop Router, refer to
“Configuring Net Link Manager” on page 733
.
Содержание BCM 3.7
Страница 1: ...Part No N0008589 3 3 December 2006 Business Communications Manager 3 7 Programming Operations Guide...
Страница 4: ...4 Software licensing N0008589 3 3...
Страница 32: ...32 Contents N0008589 3 3 W 937 Index 939...
Страница 46: ...46 Tables N0008589 3 3...
Страница 64: ...64 How to get help N0008589 3 3...
Страница 90: ...90 Manually activating Telnet N0008589 3 3...
Страница 116: ...116 Delayed system restart N0008589 3 3...
Страница 194: ...194 Configuring a data module N0008589 3 3...
Страница 276: ...276 Setting line telco features N0008589 3 3...
Страница 310: ...310 Using COS passwords N0008589 3 3...
Страница 364: ...364 Enhanced 911 E911 configuration N0008589 3 3...
Страница 380: ...380 Renumbering DNs N0008589 3 3...
Страница 398: ...398 Saving wizard pages on your computer N0008589 3 3...
Страница 458: ...458 Voice Mail settings N0008589 3 3...
Страница 488: ...488 Setting system telco features N0008589 3 3...
Страница 508: ...508 Other programming that affects public networking N0008589 3 3...
Страница 522: ...522 PRI networking using Call by Call services N0008589 3 3...
Страница 592: ...592 Monitoring Hunt groups N0008589 3 3...
Страница 636: ...636 Configuring Double Density N0008589 3 3...
Страница 640: ...640 Using the Network Update Wizard N0008589 3 3...
Страница 666: ...666 Importing and Exporting DHCP data N0008589 3 3...
Страница 722: ...722 Restarting the router N0008589 3 3...
Страница 726: ...726 Important Web Cache considerations N0008589 3 3...
Страница 748: ...748 Configuring an Interface with NAT N0008589 3 3...
Страница 794: ...794 IPSec N0008589 3 3...
Страница 818: ...818 Configuring the Policy Agent characteristics N0008589 3 3...
Страница 832: ...832 Firewall rules for Business Communications Manager with Dialup interfaces N0008589 3 3...
Страница 876: ...876 ISDN Programming N0008589 3 3...
Страница 1004: ...1004 Index N0008589 3 3...