Avaya Business Secure Router 222 Configuration - Basics Bedienungsanleitung Seite 216

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 451
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 215
216 Chapter 13 VPN
NN47922-500
NAT traversal solves the problem by adding a UDP port 500 header to the IPSec
packet. The NAT router forwards the IPSec packet with the UDP port 500 header
unchanged. VPN switch B checks the UDP port 500 header and responds. VPN
switches A and B build a VPN connection.
NAT Traversal configuration
Enable or disable NAT traversal in the VPN Branch Office Rule Setup screen
(see Figure 72 on page 223). For NAT traversal to work, you must:
Use ESP security protocol (in either transport or tunnel mode)
Use IKE keying mode
Enable NAT traversal on both IPSec endpoints
In order for VPN switch A (see Figure 72 on page 223) to receive an initiating
IPSec packet from VPN switch B, set the NAT router to forward UDP port 500 to
VPN switch A.
Preshared key
A preshared key identifies a communicating party during a phase 1 IKE
negotiation (see “IKE phases” on page 238 for more information). It is called
preshared because you have to share it with another party before you can
communicate with them over a secure connection. For Contivity Client VPN
connections, the Business Secure Router generates the preshared key from the
username and password.
Configuring Contivity Client VPN Rule Setup
Select one of the VPN rules in the VPN Summary screen and click Edit to
configure the rules settings. If the Branch Office screen is displayed, select
Contivity Client from the Connection Type list box. The VPN Contivity
Client Rule Setup screen is shown in Figure 70.
Seitenansicht 215
1 2 ... 211 212 213 214 215 216 217 218 219 220 221 ... 450 451

Kommentare zu diesen Handbüchern

Keine Kommentare