Cyclades AlterPath BladeManager Manuale delle Istruzioni Pagina 202

  • Scaricare
  • Aggiungi ai miei manuali
  • Stampa
  • Pagina
    / 240
  • Indice
  • SEGNALIBRI
  • Valutato. / 5. Basato su recensioni clienti
Vedere la pagina 201
188 MergePoint 5224/5240 Service Processor Manager Installer and Administrator Guide
IPSec VPN configuration for example 2
After the private subnets, target device and user account configuration in Two private subnets and
user configuration for example 2 on page 186 is completed, a VPN connection must be created.
This example shows the configuration steps that must be performed by the administrator and by a
user on a remote workstation for enabling two IPSec VPN connections
.
One connection supports
the IPSec VPN tunnel from the user’s workstation to sp1 and sp2. The second connection supports
the IPSec VPN tunnel to sp3 and sp4.
The administrator must also perform the following actions to enable an IPSec client to access the
private subnets where the target devices reside:
Make sure that the IPSec service is enabled on the SP manager.
Obtain the IP address of the users workstation and use it to create two named IPSec
connections (connSub1 and connSub2) with the following values specified:
Left ID: @mergepoint5224
Left IP address: 203.1.2.3 (must be one of the SP manager’s public IP addresses)
Left nexthop: leave blank if the users workstation and the SP manager are able to
exchange packets.
NOTE: The user can test whether the user’s workstation can access the SP manager by entering the SP
manager’s public IP address in a browser to try to bring up the Web Manager.
When configuring connSub1 for access to sub1: Left subnet: 192.168.1.0/24
When configuring connSub2 for access to sub2: Left subnet: 192.168.4.0/22
Right ID: @workstation
Right IP address: the IP address of the users workstation: 12.34.56.78
Right nexthop: leave blank if the users workstation and the SP manager are able to
exchange packets
Right subnet: leave blank
The other IPSec configuration parameters (such as Authentication protocol and Boot action) would
be determined by the site’s policy, equipment compatibility and site routing requirements.
NOTE: In some circumstances (for example, if packets are being blocked by a firewall on the client’s default
gateway), the user’s workstation and the SP manager are not going to be able to exchange packets. Setting one
or both of the Right and Left nexthop parameters to the IP address of a host route and selecting Add and route as
the boot action may be needed to create a route that allows the two endpoints to communicate.
In addition, the administrator must perform the following actions to enable the IPSec client to
access the subnets where the target devices reside:
Give the user a copy of the parameters used to configure the IPSec connection profiles on
the SP manager.
Vedere la pagina 201
1 2 ... 197 198 199 200 201 202 203 204 205 206 207 ... 239 240

Commenti su questo manuale

Nessun commento