Configuring A Client-To-Site Virtual Private Network (Vpn) - HP ProCurve Secure Router 7203 dl Advanced Management And Configuration Manual

Secure router
Hide thumbs Also See for ProCurve Secure Router 7203 dl:
Table of Contents

Advertisement

Configuring a Client-to-Site Virtual
Private Network (VPN)
Some employees at the Berlin office need to access the private network when
they are away from the office. For example, they may need to check their email
or download a file stored on a private network server. A VPN connection
allows such employees to access the private network from a remote location.
Berlin administrators purchase the IPSec VPN module for the ProCurve
Secure Router that connects the Berlin network to the Internet. This router
can now act as a gateway device, establishing VPN connections between
remote users and devices on the private network. In this way, mobile employ-
ees running a VPN client can use their own Internet connections to access the
private network remotely and securely.
As a VPN gateway, the ProCurve Secure Router that connects Berlin to the
Internet should provide these services:
establish a VPN tunnel with authenticated remote users
provide remote users with IP addresses on the private network, as well
as other configurations such as a DNS server
The ProCurve Secure Router uses IP Security (IPSec) to secure VPN tunnels,
which are then called IPSec security associations (SAs). The Berlin router uses
Internet Key Exchange (IKE) to authenticate remote users and to negotiate
secure encryption and authentication keys for their IPSec SAs.
Berlin administrators decide to use a preshared key to authenticate remote
users. They will issue the same key to all users allowed to access the private
network remotely. For extra security, the router will also use Extended
authentication (Xauth), which requires a remote user to enter a username and
password that authenticates it individually. The Berlin LAN uses a TACACS+
server for authentication, authorization, and accounting (AAA) functions. The
router will look for a remote user's authentication information in the
TACACS+ server's database.
The Berlin router uses IKE mode config to issue IP addresses and other
configurations to remote users.
For more information on configuring a VPN, see Chapter 8: Virtual Private
Networks.
Appendix A: Example Configuration

Configuring a Client-to-Site Virtual Private Network (VPN)

A-27

Advertisement

Table of Contents
loading

This manual is also suitable for:

Procurve secure router 7102 dl

Table of Contents