Digi TransPort WR31 User Manual page 425

Hide thumbs Also See for TransPort WR31:
Table of Contents

Advertisement

Configure Virtual Private Networking (VPN)
Logic flow for VPN Concentrator acting as a responder to a session initiated from the remote
site
1 When a remote site needs to create an IPsec SA with the VPN Concentrator it sends an IKE
request to the VPN Concentrator.
2 The VPN Concentrator needs to be able to confirm that the remote device is authorized to create
an IPsec tunnel. The remote site supplies its ID to the host during the IKE negotiations. The VPN
Concentrator uses this ID in a search of the IPsec tunnels configured and dynamic IPsec tunnels
to see if the supplied ID matches the configured Peer ID (peerid). If a match is found, the MYSQL
database is queried to retrieve the information required to complete the negotiation (such as
pre-shared key/password). If no matching base IPsec tunnel is found, router uses the local user
configuration to locate the password, and a normally configured IPsec tunnel must also exist.
3 Once the information is retrieved from the MySQL database, IKE negotiations continue, and the
created IPsec SAs will be associated with the dynamic IPsec tunnel.
4 As long as the dynamic IPsec tunnel exists, it behaves just like a normal IPsec tunnel. such as SAs
being replaced/removed as required.
5 If errors are received from the MySQL database, or not enough fields are returned, the dynamic
IPsec tunnel is removed, and IKE negotiations in progress are terminated.
6 There are a limited number of dynamic IPsec tunnels. If the number of free dynamic IPsec tunnel
is less than 10 percent of the total number of dynamic IPsec tunnel, the router periodically
removes the oldest dynamic IPsec tunnel. This is done to ensure that there will always be some
free dynamic IPsec tunnel available for incoming connections from remote routers. To view the
current dynamic tunnels that exist using the WEB server, browse to Management >
Connections > Virtual Private Networking (VPN) > IPsec. The table indicates the base IPsec
tunnel and the Remote Peer ID in the status display, to help identify which remote sites are
currently connected.
Digi TransPort WR Routers User Guide
IPsec parameters
425

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents