Chapter 8 Configuring IPSec mobility and persistent mode
149
Nortel VPN Router Configuration — Basic Features
IPSec mobility on Nortel VPN Router
Nortel VPN Router provides a new concept of IPSec mobility. The Nortel VPN
Router IPSec implementation allows support for mobile clients to maintain tunnel
connectivity while roaming from one access point to another. It maintains
TCP-based applications and provides minimum disruptions to UDP-based
applications.
With IPSec mobility, configuration parameters are passed to the Nortel VPN
Router client after a successful IPSec tunnel establishment that instruct the client
to operate in IPSec mobility mode. These parameters force the client to monitor
and communicate any address changes due to roaming to the server. When a
mobile node changes its IP address, the client is notified by the operating system
of the change. The IP address change is then communicated to the Nortel VPN
Router so that the IKE and IPSec SA databases are updated with the new address.
ISAKMP informational exchange messages are used to send the change to the
Nortel VPN Router. Once a notify message with a new client IP address is
received by the Nortel VPN Router, it updates its databases, uses the received IP
as the outer IP address, and responds to the client with an acknowledgment.
Roaming performance factors
Factors that impact the performance of the roaming on the Nortel VPN Router:
•
How quickly the adaptor or operating system detects changes in interface state
•
DHCP settings of the PC or the DHCP server
•
How quickly the operating system acquires the new IP address from the
network
•
Network delays or congestion
Logging and status for clients and servers
The Nortel VPN Client logs events to the log file. This includes events such as
Nortel VPN Client sending messages that the IP address changed, and receiving
acknowledgement that these messages were received by the Nortel VPN Router.
Содержание Contivity 1050
Страница 10: ...10 Contents NN46110 500 ...
Страница 14: ...14 Tables NN46110 500 ...
Страница 22: ...22 Preface NN46110 500 ...
Страница 58: ...58 Chapter 2 Getting started NN46110 500 ...
Страница 74: ...74 Chapter 3 Setting up the Nortel VPN Router 1010 1050 and 1100 NN46110 500 ...
Страница 90: ...90 Chapter 4 Configuring user tunnels NN46110 500 ...
Страница 118: ...118 Chapter 5 Configuring the system NN46110 500 ...
Страница 162: ...162 Chapter 8 Configuring IPSec mobility and persistent mode NN46110 500 ...
Страница 164: ...164 Branch office quick start template NN46110 500 ...
Страница 178: ...178 Index NN46110 500 W Web browser interface 50 Web interface options 53 Welcome display 56 ...