Avaya Business Secure Router 252 Configuration - Basics Uživatelský manuál Strana 214

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 460
  • Tabulka s obsahem
  • ŘEŠENÍ PROBLÉMŮ
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 213
214 Chapter 13 VPN
NN47923-500
NAT traversal solves the problem by adding a UDP port 500 header to the IPSec
packet. The NAT router forwards the IPSec packet with the UDP port 500 header
unchanged. IPSec router B checks the UDP port 500 header and responds. IPSec
routers A and B build a VPN connection.
NAT Traversal configuration
Enable or disable NAT traversal in the VPN Branch Office Rule Setup screen
(see Figure 71 on page 222). For NAT traversal to work, you must:
Use ESP security protocol (in either transport or tunnel mode)
Use IKE keying mode
Enable NAT traversal on both IPSec endpoints
In order for IPSec router A (see Figure 71 on page 222) to receive an initiating
IPSec packet from IPSec router B, set the NAT router to forward UDP port 500 to
IPSec router A.
Preshared key
A preshared key identifies a communicating party during a phase 1 IKE
negotiation (see “IKE phases” on page 238 for more information). It is called
preshared because you have to share it with another party before you can
communicate with them over a secure connection. For Contivity Client VPN
connections, the Business Secure Router generates the preshared key from the
username and password.
Configuring Contivity Client VPN Rule Setup
Select one of the VPN rules in the VPN Summary screen and click Edit to
configure the rule. If the Branch Office screen is displayed, select Contivity
Client from the Connection Type list box. The VPN Contivity Client Rule
Setup screen is shown in Figure 69.
Zobrazit stránku 213
1 2 ... 209 210 211 212 213 214 215 216 217 218 219 ... 459 460

Komentáře k této Příručce

Žádné komentáře