Frequently Asked Vpn Questions - Motorola AP-7131N-FGR Product Reference Manual

Hide thumbs Also See for AP-7131N-FGR:
Table of Contents

Advertisement

B.2.3 Frequently Asked VPN Questions
The following are common questions that arise when configuring a VPN tunnel.
Question 1: Does the access point IPSec tunnel support multiple subnets on the
other end of a VPN concentrator?
Yes. The access point can access multiple subnets on the other end of the VPN Concentrator
from the access point's Local LAN Subnet by:
• Creating multiple VPN Tunnels. The AP supports a maximum of 25 tunnels.
• When using the Remote Subnet IP Address with an appropriate subnet mask, the AP can
access multiple subnets on the remote end.
For example: If creating a tunnel using 192.168.0.0/16 for the Remote Subnet IP address, the
following subnets could be accessed:
192.168.1.x
192.168.2.x
192.168.3.x, etc
• Question 2: Even if a wildcard entry of "0.0.0.0" is entered in the Remote Subnet
field in the VPN configuration page, can the AP access multiple subnets on the
other end of a VPN concentrator for the APs LAN/WAN side?
No. Using a "0.0.0.0" wildcard is an unsupported configuration. In order to access multiple
subnets, the steps in Question #1 must be followed.
Question 3: Can the AP be accessed via its LAN interface of AP#1 from the local
subnet of AP#2 and vice versa?
Yes.
Question 4: Will the default "Manual Key Exchange" settings work without making
any changes?
No. Changes need to be made. Enter Inbound and Outbound ESP Encryption keys on both
APs. Each one should be of 16 Hex characters (depending on the encryption or
authentication scheme used). The VPN tunnel can be established only when these
corresponding keys match. Ensure the Inbound/Outbound SPI and ESP Authentication Keys
have been properly specified.
Question 5: Can a tunnel between an AP-7131N-FGR and WS2000 be established?
Yes.
Usage Scenarios
B-15

Advertisement

Table of Contents
loading

Table of Contents