18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 14: Configuring Virtual Private Networks<br />

Example VPN Scenarios<br />

452<br />

• Remote IP = 100.1.1.1<br />

• Client Address Pool = <br />

• Local Network / IP = 250.1.1.0/24<br />

• Remote Network / IP = 50.1.0.0/16<br />

Note: When configuring the <strong>Sidewinder</strong> <strong>G2</strong> named fw.west.example.com, the<br />

Local Network/IP and the Remote Network/IP values are reversed and the<br />

Remote IP value is 200.1.1.1.<br />

2 On the Authentication tab:<br />

• Authentication method = password<br />

• Enter password = samplepassword<br />

• Verify password = samplepassword<br />

3 On the Crypto tab: Order the algorithms to match that <strong>of</strong> the other<br />

<strong>Sidewinder</strong> <strong>G2</strong>.<br />

4 On the Advanced tab: No changes needed.<br />

5 Click Add to save the new VPN security association.<br />

6 Click the Save icon.<br />

Summary<br />

And that is it. The VPN can be used as soon as the other <strong>Sidewinder</strong> <strong>G2</strong> is<br />

configured. The same type <strong>of</strong> information is entered at the other <strong>Sidewinder</strong><br />

<strong>G2</strong>, changing the IP addresses as appropriate.<br />

Scenario 2: Simple deployment <strong>of</strong> remote users<br />

A common reason for using a VPN is to allow your travelling employees to<br />

connect to your corporate network from a remote site. This connection is<br />

typically made between an employee’s laptop computer and your corporate<br />

<strong>Sidewinder</strong> <strong>G2</strong>. In this type <strong>of</strong> VPN association, single (also known as “selfsigned”)<br />

certificates are generated by the <strong>Sidewinder</strong> <strong>G2</strong> and distributed to<br />

each client. This type <strong>of</strong> VPN can be used with dynamic IP-assigned clients<br />

and gateways. One association must be created for each client, so this type <strong>of</strong><br />

VPN is typically used only if you have a small number <strong>of</strong> remote clients.<br />

The following figure provides the sample configuration information used in this<br />

scenario. Note that the remote end <strong>of</strong> this VPN connection (from the<br />

<strong>Sidewinder</strong> <strong>G2</strong> point <strong>of</strong> view) is a laptop that will be using a dynamic IP<br />

address.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!