Security Settings - Motorola Netopia 2200 Administrator's Handbook

Motorola router administrator’s handbook
Hide thumbs Also See for Netopia 2200:
Table of Contents

Advertisement

Administrator's Handbook

Security Settings

Security settings include the Firewall, Packet Filtering, Stateful Inspection, and IPSec parameters.
Firewall Settings
set security firewall option [ high | medium | low | off ]
The firewall settings are discussed on page
page
21.
SafeHarbour IPSec Settings
SafeHarbour VPN is a tunnel between the local network and another geographically dispersed network
that is interconnected over the Internet. This VPN tunnel provides a secure, cost-effective alternative to
dedicated leased lines. Internet Protocol Security (IPsec) is a series of services including encryption,
authentication, integrity, and replay protection. Internet Key Exchange (IKE) is the key management pro-
tocol of IPsec that establishes keys for encryption and decryption. Because this VPN software imple-
mentation is built to these standards, the other side of the tunnel can be either another Motorola
®
Netopia
unit or another IPsec/IKE based security product. For VPN you can choose to have traffic
authenticated, encrypted, or both.
®
When connecting the Motorola Netopia
unit in a telecommuting scenario, the corporate VPN settings
®
will dictate the settings to be used in the Motorola Netopia
unit. If a parameter has not been specified
from the other end of the tunnel, choose the default unless you fully understand the ramifications of
your parameter choice.
set security ipsec option (off) {on | off}
Turns on the SafeHarbour IPsec tunnel capability. Default is off.
set security ipsec tunnels name "123"
The name of the tunnel can be quoted to allow special characters and embedded spaces.
set security ipsec tunnels name "123" tun-enable {on | off}
This enables this particular tunnel. Currently, one tunnel is supported.
set security ipsec tunnels name "123" dest-ext-address ip-address
Specifies the IP address of the destination gateway.
set security ipsec tunnels name "123" dest-int-network ip-address
Specifies the IP address of the destination computer or internal network.
set security ipsec tunnels name "123" dest-int-netmask netmask
Specifies the subnet mask of the destination computer or internal network. The subnet mask specifies
which bits of the 32-bit IP address represents network information. The default subnet mask for most
networks is 255.255.255.0 (class C subnet mask).
188

Advertisement

Table of Contents
loading

Table of Contents