Nat Traversal Configuration; Preshared Key; Configuring Contivity Client Vpn Rule Setup - Nortel BSR252 Configuration - Basics

Business secure router
Hide thumbs Also See for BSR252:
Table of Contents

Advertisement

214 Chapter 13 VPN
NAT traversal solves the problem by adding a UDP port 500 header to the IPSec
packet. The NAT router forwards the IPSec packet with the UDP port 500 header
unchanged. IPSec router B checks the UDP port 500 header and responds. IPSec
routers A and B build a VPN connection.

NAT Traversal configuration

Enable or disable NAT traversal in the VPN Branch Office Rule Setup screen
(see
In order for IPSec router A (see
IPSec packet from IPSec router B, set the NAT router to forward UDP port 500 to
IPSec router A.

Preshared key

A preshared key identifies a communicating party during a phase 1 IKE
negotiation (see
preshared because you have to share it with another party before you can
communicate with them over a secure connection. For Contivity Client VPN
connections, the Business Secure Router generates the preshared key from the
username and password.

Configuring Contivity Client VPN Rule Setup

Select one of the VPN rules in the VPN Summary screen and click Edit to
configure the rule. If the Branch Office screen is displayed, select Contivity
Client from the Connection Type list box. The VPN Contivity Client Rule
Setup screen is shown in
NN47923-500
Figure 71 on page
222). For NAT traversal to work, you must:
Use ESP security protocol (in either transport or tunnel mode)
Use IKE keying mode
Enable NAT traversal on both IPSec endpoints
"IKE phases" on page 238
Figure 71 on page
for more information). It is called
Figure
69.
222) to receive an initiating

Advertisement

Table of Contents
loading

Table of Contents