Telecommuter Vpn/Ipsec Examples; Table 17-12 Telecommuter And Headquarters Configuration Example - ZyXEL Communications Prestige 653HWI series User Manual

Adsl security gateway with ieee802.11g and isdn backup
Hide thumbs Also See for Prestige 653HWI series:
Table of Contents

Advertisement

17.16 Telecommuter VPN/IPSec Examples

The following examples show how multiple telecommuters can make VPN connections to a single Prestige at
headquarters from remote IPSec routers that use dynamic WAN IP addresses.
17.16.1
Telecommuters Sharing One VPN Rule Example
Multiple telecommuters can use one VPN rule to simultaneously access a Prestige at headquarters. They
must all use the same IPSec parameters (including the pre-shared key) but the local IP addresses (or ranges of
addresses) cannot overlap. See the following table and figure for an example.
Having everyone use the same pre-shared key may create a vulnerability. If the pre-shared key is
compromised, all of the VPN connections using that VPN rule are at risk. A recommended alternative is to
use a different VPN rule for each telecommuter and identify them by unique IDs (see section 17.16.2 for an
example)

Table 17-12 Telecommuter and Headquarters Configuration Example

My IP Address:
Secure Gateway
IP Address:
VPN Screens
TELECOMMUTER
0.0.0.0 (dynamic IP address
assigned by the ISP)
Public static IP address or domain
name.
Prestige 653HWI Series User's Guide
HEADQUARTERS
Public static IP address
0.0.0.0 With this IP address only the
telecommuter can initiate the IPSec tunnel.
17-25

Advertisement

Table of Contents
loading

Table of Contents