Ipsec Pass-Through - Panasonic KX-NS1000 Installation Manual

Pure ip-pbx
Hide thumbs Also See for KX-NS1000:
Table of Contents

Advertisement

8.6.19 IPsec Pass-through

Installation Manual References
5.9.3 Installing SIP Phones at a Remote Site
5.9.4 Installing IP Phones at a Remote Site with a Built-in Media Relay Gateway
Feature Guide References
5.2.3 Peer-to-Peer (P2P) Connection
8.6.19 IPsec Pass-through
Description
For VPN packets that use IPsec and are sent and received from a specified device on the LAN, you can
configure settings so that (1) the port number is not changed when these packets are sent and received and
(2) these packets are allowed to cross the LAN–WAN boundary uninhibited.
Only 1 device on the LAN can be designated as the IPsec pass-through device.
Setting
Application
Protocol/Protocol number
Port number
A VPN that uses IPsec is a tunnelling protocol, so the send/receive port number for packets additionally
indicates which tunnelling protocol the packets are using. If the port number is changed by the dynamic NAPT
(IP masquerade) feature, the information that indicates the tunnelling protocol will be lost, and end-to-end
communication will be impossible.
To allow end-to-end communication, specified packets from a specified device are allowed to pass through
the WAN–LAN boundary without having their port number changed.
Conditions
The IPsec pass-through feature cannot be used together with the PBX's IPsec feature or the VPSS feature.
This is because when IPsec packets pass through to the LAN, they cannot be distinguished from VPN
(IPsec) packets for the KX-NS1000.
Communication across the WAN–LAN boundary is subject to the following conditions:
IKE
must be able to be initiated from the WAN side.
*4
The first ESP
*1
ESP: Encapsulating Security Payload
*2
ISAKMP: Internet Security Association Key Management Protocol
*3
NAT-T: NAT Traversal
*4
IKE: Internet Key Exchange
PC Programming Manual References
27.11 Router Configuration—VPN—[3-3] Pass Through
360
Installation Manual
IPsec
ESP
/ 50
*1
UDP/500: ISAKMP
UDP/4500: NAT-T
packet must be able to be sent from either the LAN side or the WAN side.
*1
Description
*2
*3

Advertisement

Table of Contents
loading

Table of Contents