3Com 3C8S5907 User Guide - Page 71

Creating a VPN for, a Remote Office, the Configuring Wide Area Networking Using PPP - officeconnect

Page 71 highlights

71 At the central site, follow these steps: 1 Configure the L2Tunnel service (see the Configuring L2Tunnel Connections chapter in Using Enterprise OS Software) to enable the PathBuilder switch as a tunnel terminator. 2 Configure the firewall device if present, or the PathBuilder switch, to allow tunnel traffic through (see the Building Internet Firewalls chapter in Using Enterprise OS Software). 3 Configure the RAS service to allow authentication of the user by a server, such as a RADIUS server (see the Configuring Remote Access Services chapter in Using Enterprise OS Software). 4 Enable PPP encryption to allow encryption keys to be used by MPPE (see the Configuring Wide Area Networking Using PPP chapter in Using Enterprise OS Software). Creating a VPN for a Remote Office You can create a VPN to connect a remote office PathBuilder switch to the central site through the ISP using tunneling protocols such as the point-to-point tunneling protocol (PPTP). Figure 20 shows a typical configuration. In this configuration, the tunnel is established between the remote office and the central site. The ISP provides access to the shared network but does not interact in the tunneling setup. Figure 20 Remote Office Tunnel Remote office !V1 !1 NERToBuutieldr er OCOFNFNIECCET LAN Send ISDN Link Active WAN Connect Fault System Run Load Line Active Fault Line Act LEirnreor Fault B1 B2 Test Status Alert Pwr Fwd OfficeConnect bridge/router PPTP or L2TP tunnel ISP Firewall or CSU/DSU (optional) Central site PathBuilder switch The connection process typically follows this order: s The remote office OfficeConnect NETBuilder bridge/router dials the ISP. s The ISP assigns an IP address to the remote office bridge/router.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190

71
At the central site, follow these steps:
1
Configure the L2Tunnel service (see the Configuring L2Tunnel
Connections chapter in
Using Enterprise OS Software
) to enable the
PathBuilder switch as a tunnel terminator.
2
Configure the firewall device if present, or the PathBuilder switch, to
allow tunnel traffic through (see the Building Internet Firewalls chapter in
Using Enterprise OS Software
).
3
Configure the RAS service to allow authentication of the user by a server,
such as a RADIUS server (see the Configuring Remote Access Services
chapter in
Using Enterprise OS Software
).
4
Enable PPP encryption to allow encryption keys to be used by MPPE (see
the Configuring Wide Area Networking Using PPP chapter in
Using
Enterprise OS Software
).
Creating a VPN for
a Remote Office
You can create a VPN to connect a remote office PathBuilder switch to
the central site through the ISP using tunneling protocols such as the
point-to-point tunneling protocol (PPTP). Figure 20 shows a typical
configuration. In this configuration, the tunnel is established between the
remote office and the central site. The ISP provides access to the shared
network but does not interact in the tunneling setup.
Figure 20
Remote Office Tunnel
The connection process typically follows this order:
The remote office OfficeConnect NETBuilder bridge/router dials the
ISP.
The ISP assigns an IP address to the remote office bridge/router.
ISP
Remote office
Central site
Firewall
or CSU/DSU
(optional)
!1
!V1
PPTP or L2TP tunnel
OfficeConnect
bridge/router
PathBuilder switch