Allied Telesis AlliedWare AR440S Manual de usuario

Busca en linea o descarga Manual de usuario para Routers Allied Telesis AlliedWare AR440S. Allied Telesis AlliedWare AR440S User's Manual Manual de usuario

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 53
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 0
C613-16049-00 REV E
www.alliedtelesis.com
AlliedWare
TM
OS
How To |
Introduction
In this How To Note’s example, a headquarters office has VPNs to two branch offices and a
number of roaming VPN clients. The example illustrates the following possible components
that you could use in a corporate network:
z VPNs between a headquarters office and roaming VPN clients, such as travellers’ laptops
z VPNs between a branch office and roaming VPN clients, such as travellers’ laptops
z a VPN between a headquarters office and a branch office with a fixed IP address, when the
branch office has an ADSL PPPoA connection to the internet
z a VPN between a headquarters office and a branch office with a dynamically assigned IP
address, when the branch office has an ADSL PPPoEoA connection to the internet
z using software QoS to prioritise voice (VoIP) traffic over the VPNs
Select the solution components that are relevant for your network requirements and
internet connection type.
Contents
Which products and software versions does this information apply to? ................................... 2
Related How To Notes .......................................................................................................................... 2
About IPsec modes: tunnel and transport ......................................................................................... 3
Background: NAT-T and policies .......................................................................................................... 4
How to configure VPNs in typical corporate networks ................................................................. 6
Before you start ............................................................................................................................... 7
How to configure the headquarters VPN access concentrator ........................................... 8
How to configure the AR440S router at branch office
1
..................................................... 16
How to configure the AR440S router at branch office 2 ..................................................... 24
Configure VPNs in a Corporate Network, with
Optional Prioritisation of VoIP
Vista de pagina 0
1 2 3 4 5 6 ... 52 53

Indice de contenidos

Pagina 1 - How To

C613-16049-00 REV Ewww.alliedtelesis.comAlliedWareTM OSHow To |IntroductionIn this How To Note’s example, a headquarters office has VPNs to two branch

Pagina 2 - Related How To Notes

HeadquartersPage 10 | AlliedWare™ OS How To Note: VPNs for Corporate Networksremote security officers (RSOs). RSO definitions specify trusted remote a

Pagina 3

HeadquartersPage 11 | AlliedWare™ OS How To Note: VPNs for Corporate NetworksCheck that you have a 3DES feature licence for the ISAKMP policies.show f

Pagina 4 - Internet

HeadquartersPage 12 | AlliedWare™ OS How To Note: VPNs for Corporate NetworksCreate IPsec policies to bypass IPsec for ISAKMP messages and the “port f

Pagina 5

HeadquartersPage 13 | AlliedWare™ OS How To Note: VPNs for Corporate Networksz the branch office policies use a different encryption transform—3des2ke

Pagina 6

HeadquartersPage 14 | AlliedWare™ OS How To Note: VPNs for Corporate Networkscan trust traffic arriving on the dynamic interfaces because—in this exam

Pagina 7 - Before you start

HeadquartersPage 15 | AlliedWare™ OS How To Note: VPNs for Corporate NetworksThe rule for the private interface uses both source and destination addre

Pagina 8

Page 16 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 1How to configure the AR440S router at branch office 1Before you begin

Pagina 9

Page 17 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 1Create your Asymmetric Digital Subscriber Line (ADSL) connection. Asyn

Pagina 10 - Headquarters

Page 18 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 1If you need remote management access, we strongly recommend that you u

Pagina 11 - 6. Check feature licences

Page 19 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 1You need to configure dynamic PPP over L2TP to accept incoming Windows

Pagina 12

Page 2 | AlliedWare™ OS How To Note: VPNs for Corporate NetworksHow to make voice traffic high priority ...

Pagina 13

Page 20 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 1z (for site-to-site VPNs) 3DESOUTER as the encryption algorithm for ES

Pagina 14

Page 21 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 1Create your ISAKMP pre-shared key. This key is used when initiating yo

Pagina 15 - 10. Save your configuration

Page 22 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 1can trust traffic arriving on the dynamic interfaces because—in this e

Pagina 16

Page 23 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 1The rule for the private interface uses both source and destination ad

Pagina 17 - 4. Configure IP

Page 24 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 2How to configure the AR440S router at branch office 2Before you begin

Pagina 18

Page 25 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 2Create your Asymmetric Digital Subscriber Line (ADSL) connection. Asyn

Pagina 19 - 8. Check feature licences

Page 26 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 2If desired, set up the router as a DHCP server for the branch office 2

Pagina 20

Page 27 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 2Check that you have a 3DES feature licence for the ISAKMP policy.show

Pagina 21

Page 28 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 2Create another IPsec policy for direct Internet traffic from the headq

Pagina 22

Page 29 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 2Branch office 2 does not need rule 3 that the other sites have, becaus

Pagina 23 - 12. Save your configuration

Page 3 | AlliedWare™ OS How To Note: VPNs for Corporate NetworksAbout IPsec modes: tunnel and transportThis solution uses two types of VPN:z IPsec tun

Pagina 24

Page 30 | AlliedWare™ OS How To Note: VPNs for Corporate NetworksHow to make voice traffic high priorityThis is an optional enhancement to the configu

Pagina 25 - 3. Configure PPP for PPPoE

HeadquartersPage 31 | AlliedWare™ OS How To Note: VPNs for Corporate NetworksHow to prioritise outgoing VoIP traffic from the headquarters routerAdd t

Pagina 26

HeadquartersPage 32 | AlliedWare™ OS How To Note: VPNs for Corporate NetworksApply the policy to the VPN between headquarters and branch office 1.set

Pagina 27 - 7. Check feature licences

Page 33 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 1How to prioritise outgoing VoIP traffic from the branch office 1 route

Pagina 28

Page 34 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 1This example creates four triggers, which allows for up to four simult

Pagina 29 - 11. Save your configuration

Page 35 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 2How to prioritise outgoing VoIP traffic from the branch office 2 route

Pagina 30

Page 36 | AlliedWare™ OS How To Note: VPNs for Corporate NetworksHow to test your VPN solutionIf the following tests show that your tunnel is not work

Pagina 31 - 2. Reduce the MTU

Page 37 | AlliedWare™ OS How To Note: VPNs for Corporate NetworksConfiguration scripts for headquarters and branch officesThis section provides script

Pagina 32

HeadquartersPage 38 | AlliedWare™ OS How To Note: VPNs for Corporate NetworksHeadquarters VPN access concentrator's configuration# System configu

Pagina 33

HeadquartersPage 39 | AlliedWare™ OS How To Note: VPNs for Corporate Networks# DHCP configuration# If desired, use the router as a DHCP server.create

Pagina 34 - 7. Save your configuration

Page 4 | AlliedWare™ OS How To Note: VPNs for Corporate NetworksBackground: NAT-T and policiesNAT-T NAT Traversal (NAT-T) can be enabled on any of our

Pagina 35 - 5. Save your configuration

HeadquartersPage 40 | AlliedWare™ OS How To Note: VPNs for Corporate Networks# Create a group of SA specifications for the roaming VPN clients.# These

Pagina 36 - How to test your VPN solution

HeadquartersPage 41 | AlliedWare™ OS How To Note: VPNs for Corporate Networks# FIREWALL configurationenable firewallcreate firewall policy=hqenable fi

Pagina 37 - Before you use these scripts

HeadquartersPage 42 | AlliedWare™ OS How To Note: VPNs for Corporate Networks# If you configured SSH, create a rule for SSH traffic.add firewall polic

Pagina 38

Page 43 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 1Branch office 1 AR440S configuration—the PPPoA site with VPN client ac

Pagina 39

Page 44 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 1# allows incoming roaming VPN client connections. The clients can# onl

Pagina 40

Page 45 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 1# Log configuration# If desired, forward router log entries to a UNIX-

Pagina 41

Page 46 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 1# ISAKMP Configurationcreate isakmp pol=hq pe=200.200.200.1 key=1 send

Pagina 42

Page 47 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 1# Create a pair of rules to allow office-to-office payload traffic to#

Pagina 43 - Branch office

Page 48 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 2Branch office 2 AR440S configuration—the PPPoEoA site with a dynamical

Pagina 44

Page 49 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 2# DHCP configuration# If desired, use the router as a DHCP server.crea

Pagina 45

Page 5 | AlliedWare™ OS How To Note: VPNs for Corporate NetworksPolicies andinterfacesIt is useful to keep in mind that you apply firewall rules and I

Pagina 46

Page 50 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 2# Create an IPsec policy for branch 2 to headquarters VPN traffic.crea

Pagina 47

Page 51 | AlliedWare™ OS How To Note: VPNs for Corporate Networksbranch office 2# If you use telnet instead (not recommended), create a rule for it.#

Pagina 48

Page 52 | AlliedWare™ OS How To Note: VPNs for Corporate NetworksExtra configuration scripts for lab testing the VPN solutionThis section provides add

Pagina 49

USA Headquar ters | 19800 Nor th Cr eek Parkwa y | Suite 200 | Bothell | WA 98011 | USA | T: +1 800 424 4284 | F: +1 425 481 3895

Pagina 50

Page 6 | AlliedWare™ OS How To Note: VPNs for Corporate NetworksHow to configure VPNs in typical corporate networksThis section describes a typical co

Pagina 51

Page 7 | AlliedWare™ OS How To Note: VPNs for Corporate Networks2. The branch office 1 router, which provides:z an ADSL PPPoA Internet connection. Not

Pagina 52

HeadquartersPage 8 | AlliedWare™ OS How To Note: VPNs for Corporate NetworksHow to configure the headquarters VPN access concentratorBefore you begin

Pagina 53 - C613-16049-00 REV E

HeadquartersPage 9 | AlliedWare™ OS How To Note: VPNs for Corporate NetworksGive a fixed public address to the interface eth0, which is the Internet c

Comentarios a estos manuales

Sin comentarios