Voice over Wireless LAN Solution Guide v1.0 December 2005
______________________________________________________________________________________________________
Page 24
Figure 9: VPN design over L3 networks
In general, make the VPN Router public interface the default gateway for the handsets, and if not
the direct gateway for clients, at least ensure that traffic comes from the WLAN into the public
interface, not the private interface. Connect the private interface of the VPN Router to the trusted
side of the network. Ensure that client DHCP traffic flows through the VPN Router. If a network
path around the VPN Router exists for the handsets to get DHCP assignments (as shown in
Figure 10), then the routing requirements on the VPN Router become much more complicated.
To support such a scenario, you would need to set up static routes on the public interface as well
as inject those routes into the routing protocol on the private interface. Because of this, Nortel
generally does not recommend the network design shown in Figure 10 as a design for the VPN
feature.