Configuring a Virtual Private Network

Network-to-Network

The following examples shows how to configure a network-to-network IPsec tunnel. This example uses the X.509 Certificate authentication method, so it includes the configuration requirements for the X.509 certificate. NAT Traversal (NAT_T) is enabled in this example (on both sides) because the VPN tunnel is going private network to public network to private network. Notice also that the serial devices connected to the IOLAN can be accessed by the VPN tunnel, since they are included in the network configuration as part of the 172.16.45.0 subnetwork.

Left

172.16.45.1

Unencrypted

Data

External IP Address

External IP Address

Right

196.15.23.56

199.15.23.56

Remote VPN

 

 

Router

Router

Gateway

 

Internet

172.16.45.99

192.168.45.99

192.168.45.45

IPsec Tunnel--Encrypted Data

 

 

Unencrypted

 

 

Data

172.16.45.23

172.16.45.84

192.168.45.87

192.168.45.12

1.Configure the IPsec tunnel in the IOLAN:

2.Click the Remote Validation Criteria button and enable and populate the fields that are required for the remote X.509 certificate validation. If you just want to validate the X.509 certificate signer, you do not need to enable any of the remote validation criteria fields.

330

IOLAN Device Server User’s Guide, Version 3.6

Page 330
Image 330
Perle Systems STS, SCS manual Network-to-Network, 172.16.45.84 192.168.45.87 192.168.45.12