Tunneling To Ces When Instant Internet Has A Static Ip Address - Nortel BayStack Instant Internet 100-S Using Manual

Nortel baystack 100-s: user guide
Hide thumbs Also See for BayStack Instant Internet 100-S:
Table of Contents

Advertisement

188
Chapter 6 IP security and VPN
It is important to understand that there is a separate SA for each possible
combination of subnets. For example, if the Instant Internet unit's IPsec
configuration has two local subnets and four remote subnets, then a total of eight
separate SAs exists if all subnets are communicating with each other. In this case,
the CES has four subnets listed in the Local Accessible Networks and two subnets
listed in the Remote Accessible Networks for the branch office connection.
Either gateway can establish communications as needed. For example, an SA can
be initiated by either the Instant Internet unit or by the CES. The initiator of an SA
determines the timeout for that SA. Typically, the timeouts are set the same on
each end, so this is not an issue.
When the Instant Internet unit initiates a phase 1 connection, it sets the timeout to
be the same as that used for the phase 2 SAs. This approximates the effect of
perfect forward secrecy (PFS) because the phase 1 SA expires after the specified
timeout and must be renegotiated before any phase 2 SAs can be re-keyed. Note
that when the CES initiates a phase 1 SA, it does not specify a timeout.

Tunneling to CES when Instant Internet has a static IP address

When a tunnel is established between CES and Instant Internet and the Instant
Internet unit has a static IP address, the tunnel is called a branch-to-branch tunnel.
If you have a static IP address, you can configure a branch-to-branch VPN tunnel
between Instant Internet and a CES, Network address translation (NAT) is not
normally performed through the tunnel.
300868-G
Note: When troubleshooting a VPN tunnel, remember that each of these
SAs is established as needed and each is subject to its own possible
success or failure during negotiation.
Note: If this behavior is undesirable, use the Forced Logoff parameter in
the CES to apply the specified timeout to the phase 1 SA. For details,
refer to your CES documentation.

Advertisement

Table of Contents
loading

Table of Contents