DFL-900/1500 User Manual
Virtual Private Network – Hub and Spoke VPN
As described in the Figure 2-1, we will extend to explain how to make a VPN link between Main Office (the hub) and the
branches in this chapter. The following Figure 15-1 is the real structure in our implemented process.
15.1 Demands
1.
Suppose that your company has a main office and two branch offices which communicates using a hub and spoke VPN
configuration. The main office is the hub where the VPN tunnels terminate, while Branch_1 and Branch_2 are the spokes.
The Main office has a VPN tunnel to each branch office. Branch_1 and Branch_2 has its own VPN tunnel to the hub.
Figure 15-1 The Topology of the VPN Hub (Main Office) and VPN Spoke (Branch offices)
15.2 Objectives
1.
Using the VPN hub we can create a hub and spoke VPN configuration to direct traffic through a central DFL-1500 from
one VPN tunnel to another VPN tunnel. Each VPN tunnel provides connectivity to a different remote VPN gateway. All of
the VPN Hub member tunnels can establish VPN connections with any of the other member VPN tunnels.
15.3 Methods
1.
Configuring the IKE tunnels.
2.
Configuring the WAN1-to-LAN1 Firewall Rule.
3.
Configuring the VPN Hub for the Main Office.
4.
Configuring the VPN spoke for the Branch Offices.
Virtual Private Network – Hub and Spoke VPN
This chapter introduces Hub and Spoke VPN and explains how to implement it.
131
Chapter 15
Chapter 15