Client Mode; Network Extension Mode (Nem) - Enterasys Security Router X-PeditionTM User Manual

Enterasys security router user's guide
Table of Contents

Advertisement

VPN Applications
If you filter traffic with ACLs, you will need to write an ACL similar to this example: access-
list 101 permit udp any host 192.168.57.4 eq 4500. If you enable the XSR firewall,
refer to
traffic is passing the NAT device by entering the show crypto ipsec sa command. It displays
the following sample output, citing Port 4500 and UDP-encaps(ulation).
63.81.64.58/32, UDP, 1701
ESP: SPI=6723a3c3, Transform=3DES/HMAC-SHA, Life=2384S/249895KB
Local crypto endpt.=63.81.64.89:4500, Remote crypto endpt.=63.81.64.58:20002
Encapsulation=Transport UDP-Encaps
Depending on the type of IP address management configured on the connecting site of this
application, site-to-central-site networks can be built two ways, as shown in
Private LAN
Branch LAN
Client Mode and Network Extension Mode tunnels require the use of EZ-IPSec on the client XSR,
placing the majority of the configuration effort on the central site XSR.

Client Mode

When the XSR connects to the central site tunnel server, the tunnel server assigns the client XSR an
IP address, which can be chosen from an internal pool kept by the tunnel server. Hosts residing on
the private LAN obtain IP addresses from the DHCP server running in the XSR.
Each session between a host on the private LAN and a server on the corporate network is NAT-ed.
From the corporate perspective, the entire private LAN is represented as a single IP address. Since
hosts on the private LAN are not visible from the corporate network, traffic must be initiated from
14-12 Configuring the Virtual Private Network
"Configuring Security on the XSR"
Figure 14-6
XSR/VPN Gateway
Internal NAT/
DHCP server
Addressing on this LAN segment
is hidden from the corporate
network by NAT in the XSR
XSR/VPN Gateway
DHCP relay
DHCP server
Addressing in this LAN segment
on page 16-1 for more information. You can verify
==>
63.81.64.89/32, UDP, 1701 : 490 packets
Site-to-Central-Site Topology
Client Mode
ISP NAT
VPN tunnel
Network Extension Mode
ISP NAT
VPN tunnel
is an extension of the
corporate network
XSR/Central site tunnel server
Internet
Routing
updates
DHCP server
XSR/Central site tunnel server
Internet
Routing
updates
DHCP server
Figure
14-6.
Corporate network
Corporate network

Advertisement

Table of Contents
loading

This manual is also suitable for:

X-pedition xsr

Table of Contents