C613-16049-00 REV E www.alliedtelesis.com
AlliedWareTM OSHow To |

Introduction

In this How To Note’s example, a headquarters office has VPNs to two branch offices and a
number of roaming VPN clients. The example illustrates the following possible components
that you could use in a corporate network:
zVPNs between a headquarters office and roaming VPN clients, such as travellers’ laptops
zVPNs between a branch office and roaming VPN clients, such as travellers’ laptops
za VPN between a headquarters office and a branch office with a fixed IP address, when the
branch office has an ADSL PPPoA connection to the internet
za VPN between a headquarters office and a branch office with a dynamically assigned IP
address, when the branch office has an ADSL PPPoEoA connection to the internet
zusing software QoS to prioritise voice (VoIP) traffic over the VPNs
Select the solution components that are relevant for your network requirements and
internet connection type.

Contents

Which products and software versions does this information apply to? ................................... 2
Related How To Notes .......................................................................................................................... 2
About IPsec modes: tunnel and transport ......................................................................................... 3
Background: NAT-T and policies .......................................................................................................... 4
How to configure VPNs in typical corporate networks ................................................................. 6
Before you start ............................................................... ................................................................ 7
How to configure the headquarters VPN access concentrator ........................................... 8
How to configure the AR440S router at branch office
1
..................................................... 16
How to configure the AR440S router at branch office 2 ..................................................... 24
Configure VPNs in a Corporate Network, with Optional Prioritisation of VoIP