
Router - Virtual Private Networking
NN40011-047 Issue 1.2 BCM50 Rls 6.0 11
The above diagram shows the information required for the VPN Branch setup
from switch A’s perspective:
“My” IP Address is the WAN IP address issued by the ISP (Internet
Service Provider) to switch A
Secure Gateway Address is the WAN IP address issued by the ISP to
switch B
Local IP Address Range is the range of IP Addresses used on the LAN
connected to switch A
Remote IP Address Range is the range of IP Addresses used on the
LAN connected to switch B
If a PC on switch A requests information from a PC on switch B, switch A will
initiate a VPN connection via switch B’s Secure gateway Address. Therefore,
the two LANs can communicate via the global (WAN) IP addresses specified.
From switch B’s perspective, the set information is the same but the
terminology is reversed, i.e. switch A’s “My” IP address becomes switch B’s
Secure Gateway Address and switch A’s Local IP Address Range becomes
switch B’s Remote IP Address Range etc.
Content ID & Type
Content ID and Type are extra security features that act as extra levels of
security for incoming VPN requests. They do not replace any of the possible
encryption methods (ESP, AH).
The options for type are:
IP – IP address of a computer or BCM50 Integrated Router router
Domain (DNS) – A designated domain name
E-mail – A designated e-mail address
Note: The Domain name and e-mail options do not have to actually exist and
are purely referential.
When using this feature, both local and remote (peer) Content ID and Type
will have to be specified and mirrored for either end of the VPN connection.
For example, referring back to the diagram in the VPN Branch Relationships
section, the Content ID and Type fields on switches A and B could be as
follows:
This information has to be agreed by the BCM switch administrators of both
BCM50 Integrated Router switches.
Comentários a estes Manuais