Chapter 8

8

 

VPN

 

This Chapter describes the VPN capabilities and configuration required for common situations.

Overview

This section describes the VPN (Virtual Private Network) support provided by your TW100- BRV204.

A VPN (Virtual Private Network) provides a secure connection between 2 points, over an insecure network - typically the Internet. This secure connection is called a VPN Tunnel.

There are many standards and protocols for VPNs. The standard implemented in the TW100- BRV204 is IPSec.

IPSec

IPSec is a near-ubiquitous VPN security standard, designed for use with TCP/IP networks. It works at the packet level, and authenticates and encrypts all packets traveling over the VPN Tunnel. Thus, it does not matter what applications are used on your PC. Any application can use the VPN like any other network connection.

IPsec VPNs exchange information through logical connections called SAs (Security Associa- tions). An SA is simply a definition of the protocols, algorithms and keys used between the two VPN devices (endpoints).

Each IPsec VPN has two SAs - one in each direction. If IKE (Internet Key Exchange) is used to generate and exchange keys, there are also SA's for the IKE connection as well as the IPsec connection.

There are two security modes possible with IPSec:

Transport Mode - the payload (data) part of the packet is encapsulated through encryp- tion but the IP header remains in the clear (unchanged).

The TW100-BRV204 does NOT support Transport Mode.

Tunnel Mode - everything is encapsulated, including the original IP header, and a new IP header is generated. Only the new header in the clear (i.e. not protected). This system pro- vides enhanced security.

The TW100-BRV204 always uses Tunnel Mode.

IKE

IKE (Internet Key Exchange) is an optional, but widely used, component of IPsec. IKE pro- vides a method of negotiating and generating the keys and IDs required by IPSec. If using IKE, only a single key is required to be provided during configuration. Also, IKE supports using Certificates (provided by CAs - Certification Authorities) to authenticate the identify of the remote user or gateway.

If IKE is NOT used, then all keys and IDs (SPIs) must be entered manually, and Certificates can NOT be used. This is called a "Manual Key Exchange".

When using IKE, there are 2 phases to establishing the VPN tunnel:

68

Page 71
Image 71
TRENDnet VPN Firewall Router IPSec, TW100-BRV204 does not support Transport Mode, TW100-BRV204 always uses Tunnel Mode

VPN Firewall Router, TW100-BRV204 specifications

The TRENDnet TW100-BRV204 is a versatile broadband router that caters to small office and home office environments. This device is designed to streamline connectivity and enhance network performance, making it an excellent choice for users looking to optimize their internet experience.

One of the primary features of the TW100-BRV204 is its integrated four-port 10/100 Mbps Ethernet switch, allowing users to connect multiple devices directly via Ethernet cables. This ensures fast and reliable wired connections for computers, printers, and other networked devices, reducing latency and improving overall performance.

Additionally, the router boasts a built-in firewall that provides crucial security features. The NAT (Network Address Translation) and SPI (Stateful Packet Inspection) firewalls help protect the network from external threats while allowing seamless communication between devices on the local network. This level of security is essential for small business owners who need to safeguard sensitive data.

The TW100-BRV204 also supports advanced QoS (Quality of Service) technology, which prioritizes bandwidth allocation. This ensures that critical applications, such as VoIP (Voice over Internet Protocol) and video conferencing, receive the necessary bandwidth for optimal performance. By minimizing lag and interruptions, users can maintain a smooth online experience.

Another notable characteristic of the TRENDnet TW100-BRV204 is its support for PPPoE (Point-to-Point Protocol over Ethernet) and static IP connections. This versatility makes it compatible with various types of internet service providers, ensuring that users can easily configure their network settings without hassle.

For wireless connectivity, the TW100-BRV204 is equipped with robust wireless capabilities, adhering to the 802.11g standard, allowing for wireless communication with compatible devices. Though not as speedy as the newer 802.11n or 802.11ac standards, it still offers good performance for basic browsing and streaming tasks within its range.

In summary, the TRENDnet TW100-BRV204 is an excellent choice for those seeking a reliable and secure broadband router for small office applications. With its built-in Ethernet switch, strong firewall, QoS support, and compatibility with various ISP configurations, it stands out as a dependable solution for enhancing connectivity and productivity in a compact design. Whether for business or personal use, this router offers the essential features needed to facilitate a robust network environment.