Nortel BSR252 Configuration - Basics page 228

Business secure router
Hide thumbs Also See for BSR252:
Table of Contents

Advertisement

228 Chapter 13 VPN
Table 54 VPN Branch Office rule setup
Label
Peer Content
My IP Address
Secure Gateway
Address
NN47923-500
Description
When you select IP in the Peer ID Type field, type the IP address
of the computer with which you make the VPN connection or
leave the field blank to have the Business Secure Router
automatically use the address in the Secure Gateway Address
field.
When you select DNS in the Peer ID Type field, type a domain
name (up to 31 characters) by which to identify the remote IPSec
router.
When you select E-mail in the Peer ID Type field, type an e-mail
address (up to 31 characters) by which to identify the remote
IPSec router.
The domain name or e-mail address that you use in the Content
field is used for identification purposes only and does not need to
be a real domain name or e-mail address. The domain name also
does not have to match the remote router's IP address or what
you configure in the Secure Gateway Address field.
Regardless of how you configure the ID Type and Content fields,
two active SAs cannot have both the local and remote IP address
ranges overlap between rules.
Enter the WAN IP address of your Business Secure Router. The
VPN tunnel has to be rebuilt if this IP address changes.
The following applies if this field is configured as 0.0.0.0 (the
default):
The Business Secure Router uses the current Business
Secure Router WAN IP address (static or dynamic) to set up
the VPN tunnel.
If the WAN connection goes down, the Business Secure
Router uses the dial backup IP address for the VPN tunnel
when using dial backup or the LAN IP address when using
traffic redirect.
Type the WAN IP address or the domain name (up to 31
characters) of the IPSec router with which you are making the
VPN connection. Set this field to 0.0.0.0 if the remote IPSec
router has a dynamic WAN IP address (the Key Management
field must be set to IKE). The remote address fields do not apply
when the Secure Gateway Address field is configured to 0.0.0.0.
In this case, only the remote IPSec router can initiate the VPN.
In order to have more than one active rule with the Secure
Gateway Address field set to 0.0.0.0, the ranges of the local IP
addresses cannot overlap between rules.
If you configure an active rule with 0.0.0.0 in the Secure Gateway
Address field and the full IP address range of the LAN as the
local IP address, then you cannot configure any other active rules
with the Secure Gateway Address field set to 0.0.0.0.

Advertisement

Table of Contents
loading

Table of Contents