TRENDnet TW100-BRV324 manual Connecting 2 LANs via VPN, Connecting 2 VPN Gateways

Page 77
Connecting 2 LANs via VPN

Microsoft VPN

Connecting 2 LANs via VPN

Figure 45: Connecting 2 VPN Gateways

This allows two (2) LANs to be connected. PCs on each endpoint gain secure access to the remote LAN.

The 2 LANs MUST use different IP address ranges.

The VPN Policies at each end determine when a VPN tunnel will be established, and what systems on the remote LAN can be accessed once the VPN connection is established.

It is possible to have simultaneous VPN connections to many remote sites.

73

Image 77
Contents Page Page Table of Contents Document Version1.0 P/N 956YH10001 Copyright 2007. All Rights ReservedInternet Access Features Broadband VPN Gateway FeaturesIntroduction ChapterConfiguration & Management LAN FeaturesSecurity Features Package ContentsIPSec VPN Gateway Features Microsoft VPN Gateway SupportFront-mounted LEDs Physical DetailsRear Panel Requirements InstallationProcedure Installation The Power LED should be ON5. Check the LEDs The WAN1 or WAN2 LED should be ONOverview SetupThis Chapter provides Setup details of the Broadband VPN Gateway To Do thisPreparation Configuration ProgramIf you cant connect Figure 5 Password DialogNavigation & Data Input Home ScreenWAN Port Settings WAN Port ConfigurationStatic IP Settings Data - WAN Port ScreenButtons PPPoE Dial-upData - Port Options Screen Port Options ScreenPort Options Also called Network Adapter Address or Physical Address. This is aMTU Size Bind ServicePPPoE Connection Automatic Dial-upData - LAN Port Screen LAN Port ScreenUsing the Broadband VPN Gateway s DHCP Server DHCPUsing another DHCP Server To Configure your PCs to use DHCPData - Load/Backup Screen Load/Backup ScreenAdministration Equilibrium Type has 2 optionsSetup Windows Clients PC ConfigurationTCP/IP Settings - Overview Using Specify an IP Address Checking TCP/IP Settings - Windows 9x/MEUsing DHCP Figure 14 DNS Tab Win 95/98 Figure 13 Gateway Tab Win 95/98Figure 16 Windows NT4.0 - IP Address Checking TCP/IP Settings - Windows NT4.0Figure 15 Windows NT4.0 - TCP/IP Figure 17 - Windows NT4.0 - Add Gateway Obtain an IP address from a DHCP ServerSpecify an IP Address Figure 18 Windows NT4.0 - DNS Figure 19 Network Configuration Win Checking TCP/IP Settings - Windows1. Select Control Panel - Network and Dial-up Connection Figure 20 TCP/IP Properties WinUsing a fixed IP Address Use the following IP Address 1. Select Control Panel - Network Connection Checking TCP/IP Settings - Windows XPFigure 21 Network Configuration Windows XP Figure 22 TCP/IP Properties Windows XP Checking TCP/IP Settings - Windows Vista PC Configuration Accessing AOL Internet Access1. Select Start Menu - Settings - Control Panel - Internet Options 2. Select Set up or change your Internet ConnectionLinux Clients Macintosh ClientsOther Unix Systems Fixed IP AddressStatus Screen Operation and StatusOperation Operation and Status Figure 23 General Status ScreenFirewall WAN1/2Kernel SystemPort Status Port StatusData - Port Status Screen Event Log Event LogData - Event Log Screen Internet URL LogData - URL Log System Log System LogData - System Log Screen URL Filter Dynamic DNS Static Routing QoS Internet FeaturesThe following advanced features are provided Address List PC Database Address List Address ListData - Address List Screen PC Database Screen PC Databasedress, IP Address and Certify Data - PC Database ScreenFilter Strings URL FilterData - URL Filter Screen To add an entry to the list, enter it here, and click the Add button Dynamic DNS Screen Dynamic DNSWeb Site Button Data - Dynamic DNS ScreenOverview Static RoutingStatic Routing Screen Open Routing and Remote AccessStatic Routing Data - Static Routing ScreenOther Routers on the Local LAN Configuring Other Routers on your LANLocal Router For Router As Default Route Static Routing - ExampleFor Router Bs Default Route For the Broadband VPN Gateway s Routing Tablelocal router 192.168.1.80 Broadband VPN Gateway sData - QoS Screen Based on QoS rules set below Rules Screen Security ConfigurationRules Outbound/Inbound Connection Data - Rules ScreenData - Define Firewall Rule Screen Define Firewall Rule Inbound/OutboundDest IP Log SettingAdvanced Rule Port Transfer ToSchedules Screen SchedulesTime Zone Firewall -- LogData - Log Screen Second Server Data - Services Screen ServicesAvailable Services Add New Serviceif not required MAX 3D Engine Options SecurityData - Security Screen Maximum Con Figure 41 Multi-DMZ Data - E-Mail Screen E-MailE-Mail Alert E-Mail LogSelect the desired option for sending the log by E-mail Policies VPN IPSecIPSec VPN Endpoint VPN Configurationaddress Traffic SelectorClient PC to VPN Gateway Common VPN SituationsVPN Pass-through Figure 45 Connecting 2 VPN Gateways Connecting 2 LANs via VPNPolicies Screen VPN ConfigurationVPN List OperationsCheck Log Enable/DisableCopy Adding a New Policy Figure 47 VPN Wizard - Start Screen Enable Policy General SettingsAllow NetBIOS Authentication and EncryptionESP Authentication Authentication AlgorithmESP Encryption Manual Key EncryptionESP SPI tion is enabledThis is required if either ESP Encryption or ESP Authentica IKE Internet Key ExchangeEncryption AuthenticationExchange Mode IKE SA AggressiveVPN Examples Example 1 Connecting 2 Broadband VPN GatewaysSetting LAN A GateIPSec SA Parameters Value Example 2 Windows 2000/XP Client to LANBroadband VPN Gateway Configuration Deselect Activate the default response rule. Click Next Windows Client ConfigurationFigure 50 Windows 2000/XP - Local Security Settings Figure 52 IP Filter List Figure 51 Windows 2000/XP - Policy PropertiesFigure 54 New Rule Properties IP Filter List Figure 53 Filter Properties Addressing8. Enter the Source IP address and the Destination IP address 12. Select Negotiate security this selects IKE, then click Add Figure 55 New Rule Properties Filter ActionFigure 56 Require Security Properties Windows Setting VPN SettingFigure 57 Modify Security Method Figure 58 Require Security PropertiesFigure 60 Authentication Method Figure 59 Tunnel SettingFigure 62 Windows 2000/XP Client to Broadband VPN Gateway Figure 61 Windows 2000/XP Client to Broadband VPN GatewayFigure 64 Filter List Figure 63 Filter Properties Addressing22. Click OK to save your changes, then Close Figure 66 Security Methods Figure 65 Filter ActionFigure 67 Modify Security Method Figure 68 Tunnel SettingFigure 70 DUT to Win2K Properties Figure 69 Authentication MethodFigure 71 Properties - General Tab Figure 72 Key Exchange Settings32. Click the Advanced button to see the screen below 33. Click the Methods button to see the screen belowFigure 74 IKE Security Algorithms Example 3 Windows 2000 Server to VPN GatewayFigure 75 Windows 2000/XP Client to Broadband VPN Gateway Figure 76 Broadband VPN Gateway to Windows 2000 ServerSubnet address 11.5.0.0 Address range used on the remote LAN Remote IP addressesFor a single client, this is the same as the Gateway address Figure 77 Windows 2000 Server - Addressing Windows 2000 Server ConfigurationTrusted Certificates CertificatesRequesting a Trusted Certificate Trusted CertificatesData - Private Certificate Screen Private CertificatePrivate Certificate Private Certificate RequestsUpload Button Requesting a Private CertificateNew Request ButtonSelect the desired option. RSA is recommended To add a New CRL VPN Status VPN StatusData - VPN Status Screen Microsoft VPN Server SetupData - VPN Adapter Screen UserPPTP Service Existing Users Data - User ScreenProperties ButtonService Log Status Log ScreenData - Status Log Screen Status LogWindows 98/ME Windows Client Setup1. Click Start - Settings - Dial-up Networking 2. Select Make New ConnectionWindows ME VPN Dialing Properties 2. Select Start - Settings - Dial-up NetworkingTo establish a connection Figure 93 Windows 2000 Public Network WindowsFigure 92 Windows 2000 Network Connection Figure 95 Windows 2000 Connection Availability Figure 94 Windows 2000 VPN HostFigure 96 Windows 2000 Finish Wizard Figure 98 Windows XP Network Connection Windows XPFigure 97 Windows XP Network Connection Type Figure 101 Windows XP VPN Server Figure 99 Windows XP Connection NameFigure 100 Windows XP Public Network Figure 102 Windows XP Connection Availability Other Features & Settings Data - Diagnostics Screen DiagnosticsPing DNS LookupSearch Button Data - Account Management Screen Password ScreenPassword Data - Web Management Screen Web ManagementSettings HTTPS//123.123.123.1238080 To connect from a remote PC via the InternetData - Firmware Upgrade Screen Firmware UpgradeTo perform the Firmware Upgrade Firmware UpgradeData - Backup/Restore Screen Backup/RestoreThis will delete ALL of the existing settings Default Configu- rationGeneral Problems TroubleshootingInternet Access Appendix AIt is a security risk, since the firewall is disabled Broadband VPN Gateway Appendix B SpecificationsFCC Statement FCC Radiation Exposure StatementCE Standards CE Marking WarningAppendix B - Specifications Broadband VPN Gateway User Guide
Related manuals
Manual 8 pages 5.73 Kb

TW100-BRV324 specifications

The TRENDnet TW100-BRV324 is a versatile broadband router designed to provide small to medium-sized businesses with reliable networking capabilities. One of its key features is its built-in firewall security, which ensures robust protection against unauthorized access and threats from the internet. This appliance uses Stateful Packet Inspection (SPI), providing a comprehensive barrier against a variety of cyber threats.

Equipped with a DHCP server, the TW100-BRV324 simplifies IP address assignment, allowing administrators to manage network resources efficiently. The device supports both DHCP and static IP configurations, making it flexible for various network setups. Additionally, it offers VPN pass-through capabilities, allowing secure remote access for users needing to connect to the corporate network from outside.

The TW100-BRV324 is noted for its impressive NAT (Network Address Translation) capabilities, which enable multiple devices on a local network to access the internet through a single public IP address. This feature is particularly beneficial in saving costs related to IP addresses while enhancing network management. Furthermore, it boasts an integrated 4-port switch, facilitating wired connections for several devices in a local area network (LAN).

In terms of connectivity, the router supports 10/100 Mbps Ethernet, providing sufficient bandwidth for most small business applications. The device is also easy to set up, thanks to its user-friendly web-based interface, which guides users through the configuration process. This simplicity makes it suitable for individuals with varying levels of networking expertise.

The TW100-BRV324 supports multiple connection types, including DSL and cable internet, ensuring compatibility with various ISPs. Additionally, it embeds Quality of Service (QoS) features, allowing network administrators to prioritize traffic. This is crucial for ensuring that bandwidth-intensive applications, such as video conferencing and VoIP, receive the necessary resources for optimal performance.

In summary, the TRENDnet TW100-BRV324 is a robust and feature-rich router well-suited for small to medium-sized businesses. With its combination of security features, flexible configurations, and user-friendly management tools, it offers a powerful solution for those seeking reliable network performance without the need for extensive technical knowledge.