Configuring IPSec VPN
Full or partial mesh
This installation is very similar to the simple hub and spokes installation, but instead of
connecting to a single central site, the branch is also connected to several other branch sites by
direct IPSec VPN tunnels. The configuration is therefore very similar to the previous one,
duplicated several times.
In this topology:
The Broadband Internet connection uses cable or DSL modem, with a static public IP
●
address.
There is a VPN tunnel from each spoke to the VPN hub over the Internet.
●
There is a VPN tunnel from one spoke to another spoke.
●
Only VPN traffic is allowed via the Internet connection.
●
Figure 41: Full or partial mesh
Avaya Gw
Branch
Office 1
396 Administration for the Avaya G250 and Avaya G350 Media Gateways
Hub-to-spoke IPSec VPN link
Branch-to-branch IPSec VPN link
DSL or
Cable
modem
G350
Avaya Gw
G350
Branch
Office 2
Internet
DSL or
Cable
modem
DSL or
Cable
modem
Access
Router +
VPN
termination
Main Office
Avaya Gw
G350
Branch
Office N