Allied-telesis AlliedWare AR440S Manual do Utilizador

Consulte online ou descarregue Manual do Utilizador para Hardware Allied-telesis AlliedWare AR440S. Allied Telesis AlliedWare AR440S User Manual Manual do Utilizador

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
  • Página
    / 53
  • Índice
  • MARCADORES
  • Avaliado. / 5. Com base em avaliações de clientes
Vista de página 0
C613-16049-00 REV E
www.alliedtelesis.com
AlliedWare
TM
OS
How To |
Introduction
In this How To Note’s example, a headquarters office has VPNs to two branch offices and a
number of roaming VPN clients. The example illustrates the following possible components
that you could use in a corporate network:
z VPNs between a headquarters office and roaming VPN clients, such as travellers’ laptops
z VPNs between a branch office and roaming VPN clients, such as travellers’ laptops
z a VPN between a headquarters office and a branch office with a fixed IP address, when the
branch office has an ADSL PPPoA connection to the internet
z a VPN between a headquarters office and a branch office with a dynamically assigned IP
address, when the branch office has an ADSL PPPoEoA connection to the internet
z using software QoS to prioritise voice (VoIP) traffic over the VPNs
Select the solution components that are relevant for your network requirements and
internet connection type.
Contents
Which products and software versions does this information apply to? ................................... 2
Related How To Notes .......................................................................................................................... 2
About IPsec modes: tunnel and transport ......................................................................................... 3
Background: NAT-T and policies .......................................................................................................... 4
How to configure VPNs in typical corporate networks ................................................................. 6
Before you start ............................................................................................................................... 7
How to configure the headquarters VPN access concentrator ........................................... 8
How to configure the AR440S router at branch office
1
..................................................... 16
How to configure the AR440S router at branch office 2 ..................................................... 24
Configure VPNs in a Corporate Network, with
Optional Prioritisation of VoIP
Vista de página 0
1 2 3 4 5 6 ... 52 53

Resumo do Conteúdo

Página 1 - How To

C613-16049-00 REV Ewww.alliedtelesis.comAlliedWareTM OSHow To |IntroductionIn this How To Note’s example, a headquarters office has VPNs to two branch

Página 2 - Related How To Notes

HeadquartersPage 10 | AlliedWare™ OS How To Note: VPNs for Corporate Networksremote security officers (RSOs). RSO definitions specify trusted remote a

Página 3

HeadquartersPage 11 | AlliedWare™ OS How To Note: VPNs for Corporate NetworksCheck that you have a 3DES feature licence for the ISAKMP policies.show f

Página 4 - Internet

HeadquartersPage 12 | AlliedWare™ OS How To Note: VPNs for Corporate NetworksCreate IPsec policies to bypass IPsec for ISAKMP messages and the “port f

Página 5

HeadquartersPage 13 | AlliedWare™ OS How To Note: VPNs for Corporate Networksz the branch office policies use a different encryption transform—3des2ke

Página 6

HeadquartersPage 14 | AlliedWare™ OS How To Note: VPNs for Corporate Networkscan trust traffic arriving on the dynamic interfaces because—in this exam

Página 7 - Before you start

HeadquartersPage 15 | AlliedWare™ OS How To Note: VPNs for Corporate NetworksThe rule for the private interface uses both source and destination addre

Página 8

Page 16 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 1How to configure the AR440S router at branch office 1Before you begin

Página 9

Page 17 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 1Create your Asymmetric Digital Subscriber Line (ADSL) connection. Asyn

Página 10 - Headquarters

Page 18 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 1If you need remote management access, we strongly recommend that you u

Página 11 - 6. Check feature licences

Page 19 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 1You need to configure dynamic PPP over L2TP to accept incoming Windows

Página 12

Page 2 | AlliedWare™ OS How To Note: VPNs for Corporate NetworksHow to make voice traffic high priority ...

Página 13

Page 20 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 1z (for site-to-site VPNs) 3DESOUTER as the encryption algorithm for ES

Página 14

Page 21 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 1Create your ISAKMP pre-shared key. This key is used when initiating yo

Página 15 - 10. Save your configuration

Page 22 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 1can trust traffic arriving on the dynamic interfaces because—in this e

Página 16

Page 23 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 1The rule for the private interface uses both source and destination ad

Página 17 - 4. Configure IP

Page 24 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 2How to configure the AR440S router at branch office 2Before you begin

Página 18

Page 25 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 2Create your Asymmetric Digital Subscriber Line (ADSL) connection. Asyn

Página 19 - 8. Check feature licences

Page 26 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 2If desired, set up the router as a DHCP server for the branch office 2

Página 20

Page 27 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 2Check that you have a 3DES feature licence for the ISAKMP policy.show

Página 21

Page 28 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 2Create another IPsec policy for direct Internet traffic from the headq

Página 22

Page 29 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 2Branch office 2 does not need rule 3 that the other sites have, becaus

Página 23 - 12. Save your configuration

Page 3 | AlliedWare™ OS How To Note: VPNs for Corporate NetworksAbout IPsec modes: tunnel and transportThis solution uses two types of VPN:z IPsec tun

Página 24

Page 30 | AlliedWare™ OS How To Note: VPNs for Corporate NetworksHow to make voice traffic high priorityThis is an optional enhancement to the configu

Página 25 - 3. Configure PPP for PPPoE

HeadquartersPage 31 | AlliedWare™ OS How To Note: VPNs for Corporate NetworksHow to prioritise outgoing VoIP traffic from the headquarters routerAdd t

Página 26

HeadquartersPage 32 | AlliedWare™ OS How To Note: VPNs for Corporate NetworksApply the policy to the VPN between headquarters and branch office 1.set

Página 27 - 7. Check feature licences

Page 33 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 1How to prioritise outgoing VoIP traffic from the branch office 1 route

Página 28

Page 34 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 1This example creates four triggers, which allows for up to four simult

Página 29 - 11. Save your configuration

Page 35 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 2How to prioritise outgoing VoIP traffic from the branch office 2 route

Página 30

Page 36 | AlliedWare™ OS How To Note: VPNs for Corporate NetworksHow to test your VPN solutionIf the following tests show that your tunnel is not work

Página 31 - 2. Reduce the MTU

Page 37 | AlliedWare™ OS How To Note: VPNs for Corporate NetworksConfiguration scripts for headquarters and branch officesThis section provides script

Página 32

HeadquartersPage 38 | AlliedWare™ OS How To Note: VPNs for Corporate NetworksHeadquarters VPN access concentrator's configuration# System configu

Página 33

HeadquartersPage 39 | AlliedWare™ OS How To Note: VPNs for Corporate Networks# DHCP configuration# If desired, use the router as a DHCP server.create

Página 34 - 7. Save your configuration

Page 4 | AlliedWare™ OS How To Note: VPNs for Corporate NetworksBackground: NAT-T and policiesNAT-T NAT Traversal (NAT-T) can be enabled on any of our

Página 35 - 5. Save your configuration

HeadquartersPage 40 | AlliedWare™ OS How To Note: VPNs for Corporate Networks# Create a group of SA specifications for the roaming VPN clients.# These

Página 36 - How to test your VPN solution

HeadquartersPage 41 | AlliedWare™ OS How To Note: VPNs for Corporate Networks# FIREWALL configurationenable firewallcreate firewall policy=hqenable fi

Página 37 - Before you use these scripts

HeadquartersPage 42 | AlliedWare™ OS How To Note: VPNs for Corporate Networks# If you configured SSH, create a rule for SSH traffic.add firewall polic

Página 38

Page 43 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 1Branch office 1 AR440S configuration—the PPPoA site with VPN client ac

Página 39

Page 44 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 1# allows incoming roaming VPN client connections. The clients can# onl

Página 40

Page 45 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 1# Log configuration# If desired, forward router log entries to a UNIX-

Página 41

Page 46 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 1# ISAKMP Configurationcreate isakmp pol=hq pe=200.200.200.1 key=1 send

Página 42

Page 47 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 1# Create a pair of rules to allow office-to-office payload traffic to#

Página 43 - Branch office

Page 48 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 2Branch office 2 AR440S configuration—the PPPoEoA site with a dynamical

Página 44

Page 49 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 2# DHCP configuration# If desired, use the router as a DHCP server.crea

Página 45

Page 5 | AlliedWare™ OS How To Note: VPNs for Corporate NetworksPolicies andinterfacesIt is useful to keep in mind that you apply firewall rules and I

Página 46

Page 50 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 2# Create an IPsec policy for branch 2 to headquarters VPN traffic.crea

Página 47

Page 51 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 2# If you use telnet instead (not recommended), create a rule for it.#

Página 48

Page 52 | AlliedWare™ OS How To Note: VPNs for Corporate NetworksExtra configuration scripts for lab testing the VPN solutionThis section provides add

Página 49

USA Headquar ters | 19800 Nor th Cr eek Parkwa y | Suite 200 | Bothell | WA 98011 | USA | T: +1 800 424 4284 | F: +1 425 481 3895

Página 50

Page 6 | AlliedWare™ OS How To Note: VPNs for Corporate NetworksHow to configure VPNs in typical corporate networksThis section describes a typical co

Página 51

Page 7 | AlliedWare™ OS How To Note: VPNs for Corporate Networks2. The branch office 1 router, which provides:z an ADSL PPPoA Internet connection. Not

Página 52

HeadquartersPage 8 | AlliedWare™ OS How To Note: VPNs for Corporate NetworksHow to configure the headquarters VPN access concentratorBefore you begin

Página 53 - C613-16049-00 REV E

HeadquartersPage 9 | AlliedWare™ OS How To Note: VPNs for Corporate NetworksGive a fixed public address to the interface eth0, which is the Internet c

Comentários a estes Manuais

Sem comentários