Cisco Systems RV016, RV042G manual Vpn

Page 137

VPN

9

 

Setting Up a Gateway to Gateway (Site to Site) VPN

 

 

 

 

 

-AH Hash Algorithm: The AH (Authentication Header) protocol describes the packet format and default standards for packet structure. With the use of AH as the security protocol, protection is extended forward into the IP header to verify the integrity of the entire packet. Check the box to use this feature. Then select an authentication method: MD5 or SHA1. MD5 produces a 128-bit digest to authenticate packet data. SHA1 produces a 160-bit digest to authenticate packet data. Both sides of the tunnel should use the same algorithm.

-NetBIOS Broadcast: NetBIOS broadcast messages are used for name resolution in Windows networking, to identify resources such as computers, printers, and file servers. These messages are used by some software applications and Windows features such as Network Neighborhood. LAN broadcast traffic is typically not forwarded over a VPN tunnel. However, you can check this box to allow NetBIOS broadcasts from one end of the tunnel to be rebroadcast to the other end.

-NAT Traversal: Network Address Translation (NAT) enables users with private LAN addresses to access Internet resources by using a publicly routable IP address as the source address. However, for inbound traffic, the NAT gateway has no automatic method of translating the public IP address to a particular destination on the private LAN. This issue prevents successful IPsec exchanges. If your VPN router is behind a NAT gateway, check this box to enable NAT traversal. Uncheck the box to disable this feature. The same setting must be used on both ends of the tunnel.

-Dead Peer Detection (DPD): Check the box to enable the router to send periodic HELLO/ACK messages to check the status of the VPN tunnel. This feature can be used only when it is enabled on both ends of the VPN tunnel. Specify the interval between HELLO/ACK messages (how often you want the messages to be sent).

Tunnel Backup: When DPD determines that the remote peer is unavailable, this feature enables the router to re-establish the VPN tunnel by using either an alternative IP address for the remote peer or an alternative local WAN interface. Check the box to enable this feature. Then enter the settings described below. This feature is available only if Dead Peer Detection is enabled.

Remote Backup IP Address: Specify an alternative IP address for the remote peer, or re-enter the WAN IP address that was already set for the remote gateway.

Cisco Small Business RV0xx Series Routers Administration Guide

137

Image 137
Contents Administration Guide Cisco Systems, Inc. All rights reserved 78-19576-01 B0 Other Hardware Features Viewing System Summary Information SetupPlacement Tips IntroductionSystem Management DhcpPort Management FirewallLogging System Statistics 153 VPN 122Appendix H Where to Go From Here 199 Appendix G Specifications 189Appendix E IPSec NAT Traversal 183 Appendix F Bandwidth Management 186Model RV0xx Series Router FeaturesPorts RV042 and RV042G RV082 RV016RV042 and RV042G Ports IntroductionRV042 and RV042G Status Lights RV082 Ports and Status LightsPort Description PortsLight Description Status LightsFeature Description Other Hardware FeaturesPlacement Tips Default SettingsDesktop Placement Parameter Default ValueRV042 and RV042G 58 mm apart RV082 and RV016 94 mm apart Wall MountingRack Mounting RV082 or RV016 RV042 and RV042G Internet Port Connecting the EquipmentRV082 Internet Port RV016 Internet 1 PortGetting Started with the Configuration Troubleshooting Tips Navigation Features of the User InterfaceSaving the Settings Setup WizardsPop-Up Windows HelpViewing System Summary Information Viewing System Summary Information System InformationCisco ProtectLink Web Port Information Window ConfigurationPort Statistics Viewing System Summary Information WAN information WAN StatusVPN Setting Status Firewall Setting StatusLog Setting Status DMZ informationSetup Host Name and Domain Name Setting Up the NetworkSetup Changing the device IP address IP ModeLAN Setting device IP address and subnets Enabling multiple subnets IPv4 only Setup WAN Setting Internet connection DMZ Setting Setup Editing a WAN Connection Page Page Page IPv4 IPv6 Editing a DMZ ConnectionPage Changing the Administrator Username and Password Setup To open this page Click Setup Time in the navigation tree Setting the System TimeSetting Up a DMZ Host Port Range Forwarding, Port Triggering, Setting Up Port Forwarding and Port TriggeringPort Range Forwarding Setup Adding a service Port Triggering To open this page Click Setup UPnP in the navigation tree Setting Up Universal Plug and Play UPnPSetup Adding a service Setting Up One-to-One NAT Setup Cloning a MAC Address for the Router Editing the MAC Address Clone Settings Assigning a Dynamic DNS Host Name to a WAN Interface Editing the Dynamic DNS Setup Configuring Dynamic Routing, Configuring Static Routing, Setting Up Advanced RoutingData None, RIPv1, RIPv2 Broadcast, or RIPv2 Multicast Configuring Dynamic RoutingDynamic Routing for IPv4 Prefix Length Pv6 only Enter the prefix length Configuring Static RoutingDynamic Routing for IPv6 Setting Up Advanced Routing IPv6 Transition To Go From Here Dhcp Setting Up the Dhcp Server or Dhcp RelayDhcp Wins used for Dhcp Server, IPv4 Only Dynamic IP used for Dhcp Server onlyDNS used for Dhcp Server only Assigning static IP addresses by adding devices from a list About Static IP Addresses for IPv4 OnlyAssigning static IP addresses by entering devices manually Using the Static IP List to Block Devices DNS Local Database Client Table Viewing the Dhcp Status InformationDhcp Server Router Advertisement IPv6 Dhcp System Management Setting Up Dual WAN and Multi-WAN ConnectionsSystem Management Mode Cisco RV042, RV042G, and RV082Mode Cisco RV016 Interface Setting Max Bandwidth Provided by ISP Editing the Dual WAN and Multi-WAN SettingsNetwork Service Detection Page Adding a service Page Max Bandwidth Provided by ISP Managing the Bandwidth SettingsBandwidth Management Type Appendix F, Bandwidth ManagementManaging the Bandwidth Settings Adding a service Setting Up Snmp Enabling Device Discovery with Bonjour Enabling Device Discovery with Bonjour DNS Name Lookup Using Built-In Diagnostic ToolsTo open this page Click System Management Diagnostic Ping Restoring the Factory Default Settings Upgrading the Firmware Restarting the Router Restoring the Settings from a Configuration File Backing Up and Restoring the SettingsCopying a Startup File or Mirror File Backing Up Configuration Files and Mirror FilesBacking Up and Restoring the Settings Port Management Configuring the Port SettingsPort Management Summary Viewing the Status Information for a PortStatistics Firewall Configuring the General Firewall SettingsFirewall Restrict Web Features Firewall About Access Rules Configuring Firewall Access RulesManaging Access Rules To delete all custom rules Click Restore to Default Rules Services IPv4 and IPv6 Configuring Access RulesSchedule IPv4 Only Adding a service Page Forbidden Domains, Website Blocking by Keywords, Schedule, Using Content Filters to Control Internet AccessWebsite Blocking by Keywords Forbidden DomainsSchedule Getting Started with Cisco ProtectLink Web Cisco ProtectLink WebCisco ProtectLink Web Specifying the Global Settings for Approved URLs and Clients Approved Clients Configuration Approved URL ConfigurationApproved URLs and Approved Clients To delete an entry Click the Delete iconWeb Protection Enabling Web Protection for URL FilteringURL Filtering Web Reputation Business Hour SettingURL Overflow Control Updating the ProtectLink LicenseLicense Information LicenseIntroduction to VPNs VPNConfiguration tasks Remote Access Client To GatewaySite to Site VPN Gateway To Gateway Gateway-to-Gateway VPN Tunnel Between RV0xx Series RoutersRouter QuickVPN, page125 and Remote Access with PPTP, page125Remote Access with Pptp Remote Access with Cisco QuickVPNTo open this page Click VPN Summary in the navigation tree Viewing the Summary Information for VPNTunnel Status GroupVPN Status Up a Remote Access Tunnel for VPN Clients Client To Gateway,VPN Clients Status Setting Up a Gateway to Gateway Site to Site VPN Add a New Tunnel Local Group Setup and Remote Group SetupVPN IPSec Setup Required fields for Manual mode Preshared Key, page 135 and Advanced settings for IKE withRequired fields for IKE with Preshared Key Advanced settings for IKE with Preshared Key VPN VPN RV0xx Local Group Setup Remote Client Setup for Single User Tunnel Type VPN IPSec Setup Required fields for IKE with Preshared Key Advanced settings for IKE with Preshared Key VPN Users, Certificate Management, page148 Managing VPN Users and CertificatesCertificate Management UsersSetting Up VPN Passthrough Setting Up Pptp Server Pptp Server IP Address RangeConnection List Syslog section, Mail section, Setting Up the System Log and AlertsSyslog section Log Setting, Buttons,Mail section Logging System StatisticsLog Setting Buttons Viewing the System Log Logging System Statistics Wizard Basic Setup, Access Rule Setup, page160Wizard Basic SetupAccess Rule Setup Beacon interval Term DefinitionDtim Delivery Traffic Indication MessageGlossary Term Definition Advertisement Daemon Radvd RouterRequest to Send RTS ThresholdVlan Virtual LAN RIPng RIP next generationStatic routing Your computer cannot connect to the Internet Firmware upgrade has failedRouter does not have a coaxial port for the cable connection TroubleshootingIntroduction Cisco QuickVPN for WindowsCisco QuickVPN for Windows Cisco QuickVPN Client Installation and ConfigurationUsing the Cisco QuickVPN Software Using the Cisco QuickVPN Software Topology Options Hub and Spoke VPN Hub and Spoke TopologyMesh VPN Mesh TopologyOther Design Considerations WAN SetupGateway To Gateway Tunnel with a Dynamic IP Address LAN SetupConfiguring a VPN Tunnel on a Cisco RV0xx Series Router Field Value Settings on the Site a RouterExample Sites with Static WAN IP Addresses MD5 Encryption PhaseEncryption Field ValuesExample Site with a Dynamic WAN IP Address Authentication Field Value IPSec Setup Keying Mode IKE with Preshared Key Phase Overview IPSec NAT TraversalIPSec NAT Traversal Configuration of Router aConfiguration of Router B Click Add to List Creation of New ServicesClick the System Management tab Bandwidth Management Creation of New Bandwidth Management RulesClick Save RV042 SpecificationsPerformance SecurityQoS SpecificationsNetwork Environmental RV042GManagement Operating System Linux VPN Cisco RV082 IKE Cisco RV016 Dhcp DNS NAT DMZ Built-in Pptp server supporting 10 Pptp clients Cisco Small Business SupportProduct Documentation
Related manuals
Manual 2 pages 47.87 Kb