Designing Access Controls

Lay Out the Network

(However, even some homes feature simple LANs.) If the remote endpoint does have a NATed IP address, the VPN gateway must support NAT Traversal (NAT-T); otherwise, the VPN connection fails.

The Secure Router 7000dl supports NAT-T in addition to the VPN capabilities listed in Table 3-116.

Table 3-116. VPN Capabilities of the ProCurve Secure Router 7000dl Series

Module

VPN Protocol

Maximum

Encryption and

Support for NAT-T

Support for Xauth

 

 

Number of

Hash Algorithms

 

 

 

 

Tunnels

 

 

 

 

 

 

 

 

 

IPSec VPN Base

IPsec with IKE 10

Module (J9026A)

IPsec with

 

 

manual keying

• Hash:

Yes

Yes

HMAC-MD5

HMAC- SHA1

Encryption:

DES

3DES

AES with 128-, 196-, or 256-bit keys

IPSec VPN

IPsec with IKE 1000

Module (J8471A)

IPsec with

 

 

manual keying

• AH:

Yes

Yes

MD5

SHA-1

ESP:

DES

3DES

AES with 128-, 196-, or 256-bit keys

Remote users need a VPN client on the endpoints they use to access the network. The client must, of course, support the options you have configured on your VPN gateway. Although most Windows and Mac workstations provide some form of VPN support, you might encourage or require users to install a vendor VPN client to add support for more options and possibly simplify configuration.

When you purchase the ProCurve Secure Router 7100/7200 IPSec VPN Module and IPSec Base VPN Module, you receive a 10-user license for the ProCurve VPN Client. Some capabilities of this client are listed in Table 3-117.

3-145