Supported Dvpn Features; Protocols And Standards - 3Com MSR 50 Series Configuration Manual

3com msr 30-16: software guide
Hide thumbs Also See for MSR 50 Series:
Table of Contents

Advertisement

DVPN Overview
1561
Supported DVPN
Features
n
Support for these features varies by device.
NAT traversal of DVPN packets
When the tunnel initiator resides behind a NAT gateway, a Spoke-Spoke tunnel
can be established traversing the NAT gateway. If the other end of the tunnel is
behind a NAT gateway, packets must be forwarded by a Hub before the intended
receiver originates a tunnel establishment request. If both of them reside behind
NAT gateways, no tunnel can be established between them and packets between
them will be forwarded by a Hub.
VAM client support for dynamic IP address
No tunnel destination address is required on either tunnel interface of a tunnel. A
VAM client registers its public and private addresses with the VAM server. When a
tunnel needs to be established, the VAM server sends information about the peer
client's public address, implementing dynamic tunnel establishment. When the
VAM client has its IP address changed, it reregisters with the VAM server,
supporting dynamic IP address.
AAA identity authentication of VAM clients on the VAM server
After the initialization process completes, a VAM client must register with the
VAM server, during which the client must pass identity authentication first. VAM
supports PAP authentication and CHAP authentication. The VAM server uses AAA
to authenticate clients in the VPN domain. A VAM client must pass authentication
to access the VPN.
Identity authentication of the VAM server on a VAM client
A VAM client and the VAM server must be configured with the same pre-shared
key to generate the encryption/authentication key. Meanwhile, a VAM client can
use the pre-shared key to authenticate the identity of the VAM server. This kind of
identity authentication is bi-directional.
Encryption of VAM control packets
VAM control packets can be encrypted by using AES-128, DES, or 3DES.
IPSec protection of data packets
Data packets in a DVPN tunnel can be protected by IPSec (using the ESP protocol
and IKE).
Centralized management of policies
A VAM server manages all policies in a VPN domain centrally.
Support for multiple VPN domains
A VAM server supports up to 10 VPN domains.

Protocols and Standards

Specifications of VAM.

Hide quick links:

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents