Prestige 334W User’s Guide

 

 

Table 16-11 VPN: Global Setting

 

 

 

 

 

LABEL

DESCRIPTION

 

 

 

 

 

 

Allow Through IP/Sec

Select this check box to send NetBIOS packets through the VPN connection.

 

 

Tunnel

 

 

 

 

 

 

 

Apply

Click Apply to save your changes back to the Prestige.

 

 

 

 

 

 

Reset

Click Reset to begin configuring this screen afresh.

 

 

 

 

 

16.17Telecommuter VPN/IPSec Examples

The following examples show how multiple telecommuters can make VPN connections to a single Prestige at headquarters from remote IPSec routers that use dynamic WAN IP addresses.

16.17.1Telecommuters Sharing One VPN Rule Example

Multiple telecommuters can use one VPN rule to simultaneously access a Prestige at headquarters. They must all use the same IPSec parameters (including the pre-shared key) but the local IP addresses (or ranges of addresses) cannot overlap. See the following table and figure for an example.

Having everyone use the same pre-shared key may create a vulnerability. If the pre-shared key is compromised, all of the VPN connections using that VPN rule are at risk. A recommended alternative is to use a different VPN rule for each telecommuter and identify them by unique IDs (see section 16.17.2 for an example).

Table 16-12 Telecommuter and Headquarters Configuration Example

 

TELECOMMUTER

 

HEADQUARTERS

 

 

 

My IP Address:

0.0.0.0 (dynamic IP address

Public static IP address

 

assigned by the ISP)

 

 

 

 

 

 

Secure Gateway

Public static IP address or domain

0.0.0.0

With this IP address only the

IP Address:

name.

telecommuter can initiate the IPSec tunnel.

VPN Screens

16-33