Digi TransPort WR31 User Manual page 424

Hide thumbs Also See for TransPort WR31:
Table of Contents

Advertisement

Configure Virtual Private Networking (VPN)
Logic flow: creation of IPSec SAs
Logic flow for VPN Concentrator acting as initiator
The VPN Concentrator normally acts as an initiator when it receives an IP packet for routing with a
source address matching the IPsec tunnel local subnet address & mask and a destination address
matching the remote subnet address & mask, provided an IPsec SA does not already exist for this
site.
1 If an IPsec group is configured to use the matching IPsec tunnel, the router uses a MySQL query
to obtain the site specific information in order to create the SAs.
2 The VPN Concentrator creates a SELECT query using the destination IP address of the packet
and the mask configured in the IPsec group configuration to determine the remote subnet
address. This means that the remote subnet mask must be the same on all sites using the
current IPsec group.
3 Once the site-specific information is retrieved, the router creates a dynamic IPsec Tunnel which
is based upon the base IPSec tunnel configuration plus the site specific information from the
MySQL database.
4 The router then uses the completed IPsec tunnel configuration and IKE to create the IPsec SAs.
5 For the pre-shared key, IKE uses the password returned from the MySQL database rather than
doing a local look up in the user configuration.
6 Once created, the SAs are linked with the dynamic IPsec tunnel. Replacement SAs are created as
the lifetimes start to get low and traffic is still flowing.
7 When all SAs to this remote router are removed, the dynamic IPsec tunnel is removed, allowing
reuse of the IPsec tunnel to create tunnels to other remote sites.
8 When processing outgoing packets, dynamic IPsec Tunnels are searched before base IPsec
tunnels. If a matching dynamic IPsec tunnel is found, the router uses that tunnel, and the base
IPsec tunnel is only matched if no dynamic IPsec tunnel exists.
9 Once the dynamic IPsec tunnel is removed, further outgoing packets will match the base IPsec
tunnel and the process is repeated.
Digi TransPort WR Routers User Guide
IPsec parameters
424

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents