7 VPN connection
SINAUT MD741-1
84
C79000-G8976-C236-05
Requests to the VPN gateway of the remote network
To allow an IPsec connection to be established successfully, the VPN remote
station must support IPsec with the following configuration:
●
Authentication with X.509 certificates, CA certificates or Pre Shared Key
●
ESP
●
Diffie-Hellman group 1, 2 or 5
●
3DES or AES encryption
●
MD5 or SHA-1 hash algorithms
●
Tunnel mode
●
Quick mode
●
Main mode
●
SA lifetime (1 second to 24 hours)
If the remote station is a computer with Windows 2000, the Microsoft Windows
2000 High Encryption Pack or at least service pack 2 must be installed.
If the remote station is downstream from a NAT router, the remote station must
support NAT-T. Or, the NAT router must know the IPsec protocol (IPsec/VPN
passthrough).
7.2
VPN Roadwarrior Mode
The Roadwarrior Mode
makes it possible for the SINAUT MD741-1 to accept a
VPN connection initiated by a remote station with an unknown IP address. The
remote station must authenticate itself properly; in this VPN connection there is no
identification of the remote station based on the IP address or the hostname of the
remote station.
Figure 7-1
IPsec VPN > Connections
Set the SINAUT MD741-1 up in accordance with what has been agreed with the
system administrator of the remote station.