Firewall Ipsec Configuration; Ethernet Port Configuration - RuggedCom RuggedRouter RX1000 User Manual

Ruggedcom router user manual
Hide thumbs Also See for RuggedRouter RX1000:
Table of Contents

Advertisement

RuggedRouter
User Guide
Parameters
At IPsec Startup
Authenticate by
Connection Type
Encryption Protocols
Compress Data
Perfect Forwarding Secrecy
NAT Traversal
Left System Settings
Public IP Address
System Identifier
Private subnet behind system 10.0.0.0/8
System's public key
Next hop to other system
Right System Settings
Public IP Address
System Identifier
Private subnet behind system 10.0.1.0/24
System's public key
Next hop to other system
Apply the configuration to restart the server and create an ipsec0 interface.

Firewall IPSec Configuration

Create firewall Zones "vpn" and net. Ensure that the WAN interface (here w1ppp)
and ipsec0 interface are present in the Shorewall Network Interfaces. The WAN
interfaces should be in zone "net" while ipsec0 should be in zone "vpn".
Add the following firewall rules:
Action
ACCEPT
ACCEPT
ACCEPT
ACCEPT
Restart the firewall to install the rules.

Ethernet Port Configuration

Because the remote client will be assigned a local IP address but is reachable only
through the IPSec connection, proxy ARP must be employed. Activate proxy ARP
on the Ethernet interface that hosts the local network (here eth1) via the Networking
Menu, Ethernet sub-menu boot time entry Proxy ARP setting. When a host on
eth1 arps for the remote client address, the router will answer on behalf of the client.
136
Value
Add connection
rsasig
Tunnel
As desired
As desired
As desired
No
Address or hostname ..
(IP of public gateway)
Default
Certificate File
(router.pem)
Default
Automatic
Default
Entered below (%cert)
Default
Source-Zone Destination-Zone Protocol Dest-Port
all
fw
all
fw
all
fw
vpn
loc
Comments
We wish to add the connection when the
client starts it.
X.509 certificates provide RSA
Recommend "yes"
Required when the router acts as a client and
is behind a NAT firewall.
Router's side
Laptop1 side
Assign IP based on client from within this
subnet
Derive identity from incoming certificate
ah
esp
udp
500
RuggedCom

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Ruggedrouter rx1100

Table of Contents