Adding A Remote User Ipsec Tunnel; Assigning An Ip Address To A Remote User Account - Nortel BCM 3.7 Manual

Software
Table of Contents

Advertisement

786
IPSec
Split Tunneling security considerations
Business Communications Manager takes precautions against violators potentially hacking
tunneled information when the Business Communications Manager is operating in Split Tunnel
mode.
The primary precaution is to drop packets that do not have the IP address that is assigned to the
tunnel connection as its source address. For example, if you have a PPP dial-up connection to the
Internet with an IP address of 192.168.21.3, and you set up an IPSec client connection to a
Business Communications Manager and you are assigned an IPSec client IP address of
192.192.192.192, then any packets that attempt to pass through the IPSec client tunnel connection
with a source IP address of 192.168.21.3 (or any address other than 192.192.192.192) will be
dropped.
To completely eliminate security risks, you should not use the Split Tunneling feature.

Adding a Remote User IPSec Tunnel

A Remote User IPSec Tunnel connects a remote computer to the Business Communications
Manager system.
Note: The remote computer must have version 4.60 of the Contivity VPN Client
installed.
Note: If the computer running the VPN client is not on the same subnet as the Destination
address (i.e. there is at least one router between the computer and the Business
Communications Manager), then the default Next Hop Router on the Business
Communications Manager must also be through this interface. For instructions on setting
up a default Next Hop Router, refer to

Assigning an IP Address to a Remote User Account

The Remote User account requires that an IP address is assigned to the Remote User when they log
into the Business Communications Manager. This IP address must be in the private IP network
that the Remote User is able to access.
The Business Communications Manager supports two methods of assigning an IP Address to the
Remote User Account. You can use a static IP address or a dynamic IP address from an IP Address
Pool.
Static IP Address
To assign a static IP address to the Remote User account, you must configure the following two
options when you configure the Remote User Account settings:
Static IP Address
Static Subnet Mask
N0008589 3.3
"Configuring Net Link Manager" on page
733.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Business communications manager 3.7

Table of Contents