140
Chapter 7 Configuring control tunnels
NN46110-500
In this environment, the remote Boston Nortel VPN Router is a control tunnel to
the local Cleveland Nortel VPN Router. From any system on the Cleveland
network, you can access the management address for the Boston Nortel VPN
Router. This allows systems on the Cleveland network to initiate management
operations on the Boston Nortel VPN Router, such as HTTP, FTP, and Telnet. Yet
because it is a control tunnel, users on the Cleveland private networks cannot
exchange packets with users on the private Boston Network.
Additionally, a user control tunnel is configured so that a remote user can establish
a control tunnel when using the IPsec client. You create this user account with
password authentication in the Control Tunnels group using the serial port.
Restricted mode
The Restricted mode feature prevents management of the Nortel VPN Router
except through a control tunnel. This limits the scope of management to someone
who has the proper credentials both to set up the tunnel (if it is an end user) and to
log in as an administrator (administrative access privileges). Having the proper
access privileges acts as a level of security. Additionally, since in restricted mode
you are forced to manage the Nortel VPN Router through a tunnel, you are
guaranteeing data protection through encryption.
You enable Restricted mode through the Serial Interface menu or the command
line interface available through Telnet. In Restricted mode, you can perform the
key management functions through the control tunnel, including HTTP, FTP,
SNMP, and Telnet. All other attempts to perform these actions outside of the
control tunnel will fail. You cannot enter Restricted mode unless there is an active
control tunnel. This ensures there is a mechanism to manage the Nortel VPN
Router in restricted mode.
Nailed-up control tunnels
You may want to have some control tunnels remain up even when there is no
traffic traversing the control tunnel. This is generally the case for branch office
versus end user control tunnels.
Note:
If you change any settings to the branch office connection when
using nailed up tunnels, you must bring down the tunnel for the changes
to take effect.
Содержание Contivity 1050
Страница 10: ...10 Contents NN46110 500 ...
Страница 14: ...14 Tables NN46110 500 ...
Страница 22: ...22 Preface NN46110 500 ...
Страница 58: ...58 Chapter 2 Getting started NN46110 500 ...
Страница 74: ...74 Chapter 3 Setting up the Nortel VPN Router 1010 1050 and 1100 NN46110 500 ...
Страница 90: ...90 Chapter 4 Configuring user tunnels NN46110 500 ...
Страница 118: ...118 Chapter 5 Configuring the system NN46110 500 ...
Страница 162: ...162 Chapter 8 Configuring IPSec mobility and persistent mode NN46110 500 ...
Страница 164: ...164 Branch office quick start template NN46110 500 ...
Страница 178: ...178 Index NN46110 500 W Web browser interface 50 Web interface options 53 Welcome display 56 ...