
VPN
Example 2: Windows 2000/XP Client to LAN
In this example, a Windows 2000/XP client connects to
Figure 54: Windows 2000/XP Client to VRT-401
To use 3DES encryption, you need Service Pack 3 or later installed on Windows 2000.
VRT-401 Configuration
Setting |
| Value | Notes |
|
|
|
|
Name |
| Win Client | Name does not affect operation. Select a |
|
|
| meaningful name. |
Remote Endpoint |
| 172.16.9.10 | Other endpoint's WAN (Internet) IP ad- |
|
|
| dress. |
Local |
| Subnet address: | Allows access to entire LAN. Use a more |
IP addresses |
| 192.168.0.0 | restrictive definition if possible. |
|
| 255.255.255.0 |
|
Remote |
| 172.16.9.10 | For a single client, this is the same as the |
IP addresses |
|
| Gateway. |
Key Exchange |
| IKE | Must match |
|
|
|
|
IKE SA Parameters |
|
| |
|
|
| |
IKE Direction |
| Responder | Only want to accept client connections. |
|
|
|
|
Local Identity |
| IP address | Required. |
|
|
|
|
Remote Identity |
| IP address | Required |
|
|
|
|
IKE Authentica- |
| Certificates are not widely used. | |
tion method |
|
|
|
| Xxxxxxxxxx | Must match client PC | |
|
|
|
|
IKE Authentica- |
| Must match client PC | |
tion algorithm |
|
|
|
IKE Encryption |
| 3DES | Must match client PC |
|
|
|
|
IKE Exchange |
| Main Mode | Must match client PC |
mode |
|
|
|
85