P-662HW-D Series Support Notes
The IP addresses we use in this example are as shown below.
Branch_A
Headquarter
Branch_B
WAN:202.3.1.1
LAN:192.168.3.1
WAN:202.1.1.1
LAN:192.168.1.1
WAN:202.2.1.1
LAN:192.168.2.1
LAN of Branch_A
LAN of Headquarter
LAN of Branch_B
192.168.3.0/24 192.168.1.0/24 192.168.2.0/24
Setp 1: Setup VPN in branch office A
Because VPN routing enables branch offices to talk to each other via tunnels
concentrated on headquarter. In this step, we configure an IPSec rule in
Prestige (Branch_A) for PCs behind branch office A to access both LAN
segments of headquarter and branch office B. Because the LAN segments of
headquarter and branch office B are continuous, we merge them into one
single rule by including these two segments in
Remote
section. If by any
chance, the two segments are not continuous, we strongly recommend you to
setup different rules for these segments.
Create a VPN Rule with name
Branch_A
. The configuration is the same as
Prestige to Prestige Tunnel, just the IP Address is a little different:
(1)
Local Address Type
is
Range Address
and
IP Address Start
is
192.168.3.0, IP Address End
is
192.168.3.255.
This section covers the LAN
segment of branch office A.
Remote Address Type
is
Range Address
and
IP Address Start
is
192.168.1.0
, IP Address End is
192.168.2.255
. This section covers the LAN
segment of both headquarter and branch office B.
(2)
My IP Address
is the
WAN IP of Prestige
in
Branch_A
,
202.3.1.1
in the
example.
Secure Gateway Address
is
IP address of Headquarter
,
202.1.1.1
in the
example.
(3) Suppose the pre-shared key is
01234567
, we should configure the same
key in the corresponding rule in Headquarter VPN Gateway.
(4) You can setup IKE phase 1 and phase 2 parameters by pressing
Advanced
button. Please make sure that parameters you set in this menu
match with all the parameters with the corresponding VPN rule in headquarter.
We don’t make any advanced setup in the example.
Step 2: Setup VPN in branch office B
107
All contents copyright © 2006 ZyXEL Communications Corporation.