126
Chapter 6 Configuring branch office tunnels
NN46110-500
A DNS server will be aware of all the IP addresses that correspond to a particular
domain name. When a user requests a lookup for that domain, the DNS will
provide all the known addresses in a random order. The user can pick one of the
addresses to communicate with the service. The Nortel VPN Router always uses
the first address provided. If the first address is unresponsive, the Nortel VPN
Router performs a new query.
Round Robin DNS can be used to achieve failover.
Figure 23
shows a central
office that has two Nortel VPN Routers. The first VPN Router has a public IP
address 1.2.3.4 and the second has public IP address 5.6.7.8. Both addresses have
been mapped to the same DNS name ces.lab.com. The initiator is configured with
the remote endpoint set to the domain name of the responder ces.lab.com. When
the initiator performs a DNS query, the DNS server returns IP addresses 1.2.3.4
and 5.6.7.8. The initiator selects 1.2.3.4 because it is first in the list of addresses
and establishes a tunnel. If 1.2.3.4 goes down, the initiator must reestablish the
tunnel and send a new DNS query. The DNS server returns addresses 5.6.7.8 and
1.2.3.4 because of the Round Robin operation. The initiator selects address 5.6.7.8
because it is the first in the list and establishes a tunnel with the second Nortel
VPN Router, achieving a failover.
Figure 23
Failover example
Round Robin DNS can be used to achieve a simple load balancing between Nortel
VPN Routers.
Figure 24 on page 127
shows a central office that has two Nortel
VPN Routers. The first VPN Router has public IP address 1.2.3.4 and the second
has public IP address 5.6.7.8. Both addresses are mapped to the same DNS name,
such as ces.lab.com. There are multiple branch offices and the initiators at the
Содержание Contivity 1050
Страница 10: ...10 Contents NN46110 500 ...
Страница 14: ...14 Tables NN46110 500 ...
Страница 22: ...22 Preface NN46110 500 ...
Страница 58: ...58 Chapter 2 Getting started NN46110 500 ...
Страница 74: ...74 Chapter 3 Setting up the Nortel VPN Router 1010 1050 and 1100 NN46110 500 ...
Страница 90: ...90 Chapter 4 Configuring user tunnels NN46110 500 ...
Страница 118: ...118 Chapter 5 Configuring the system NN46110 500 ...
Страница 162: ...162 Chapter 8 Configuring IPSec mobility and persistent mode NN46110 500 ...
Страница 164: ...164 Branch office quick start template NN46110 500 ...
Страница 178: ...178 Index NN46110 500 W Web browser interface 50 Web interface options 53 Welcome display 56 ...