Telecommuters Using Unique Vpn Rules Example - ZyXEL Communications P-793H v3 User Manual

P-79x series g.shdsl.bis broadband gateway
Hide thumbs Also See for P-793H v3:
Table of Contents

Advertisement

Table 57 Telecommuters Sharing One VPN Rule Example
FIELDS
Local IP Address:
Remote IP
Address:

13.6.12.2 Telecommuters Using Unique VPN Rules Example

In this example the telecommuters (A, B and C in the figure) use IPSec routers with domain names
that are mapped to their dynamic WAN IP addresses (use Dynamic DNS to do this).
With aggressive negotiation mode (see
types and contents to distinguish between VPN rules. Telecommuters can each use a separate VPN
rule to simultaneously access a P-79X at headquarters. They can use different IPSec parameters.
The local IP addresses (or ranges of addresses) of the rules configured on the P-79X at
headquarters can overlap. The local IP addresses of the rules configured on the telecommuters'
IPSec routers should not overlap.
See the following table and figure for an example where three telecommuters each use a different
VPN rule for a VPN connection with a P-79X located at headquarters. The P-79X at headquarters
(HQ in the figure) identifies each incoming SA by its ID type and content and uses the appropriate
VPN rule to establish the VPN connection.
The P-79X at headquarters can also initiate VPN connections to the telecommuters since it can find
the telecommuters by resolving their domain names.
Figure 87 Telecommuters Using Unique VPN Rules Example
192.168.2.12
192.168.3.2
192.168.4.15
Table 58 Telecommuters Using Unique VPN Rules Example
TELECOMMUTERS
All Telecommuter Rules:
My IP Address 0.0.0.0
Secure Gateway Address: bigcompanyhq.com
Remote IP Address: 192.168.1.10
Peer ID Type: E-mail
Peer ID Content: bob@bigcompanyhq.com
TELECOMMUTERS
Telecommuter A: 192.168.2.12
Telecommuter B: 192.168.3.2
Telecommuter C: 192.168.4.15
192.168.1.10
A
LAN
B
LAN
C
LAN
P-79X Series User's Guide
Chapter 13 VPN
HEADQUARTERS
192.168.1.10
0.0.0.0 (N/A)
Section 13.6.6 on page
Internet
HEADQUARTERS
All Headquarters Rules:
My IP Address: bigcompanyhq.com
Local IP Address: 192.168.1.10
Local ID Type: E-mail
Local ID Content: bob@bigcompanyhq.com
148
144), the P-79X can use the ID
HQ
LAN
192.168.1.10

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

P-792h v3P-791r v3

Table of Contents