D-Link DFL-1000 [69/168] Configuring a vpn concentrator for hub and spoke vpn

D-Link DFL-1000 [69/168] Configuring a vpn concentrator for hub and spoke vpn
DFL-1000 User Manual
6
9
When you configure the Remote Gateway, you can require users to authenticate before accessing
the remote gateway by choosing a user group in the User Group field. Selecting a user group is
optional. For information about user groups, see Adding user groups
.
Add one or more AutoIKE key VPN tunnels that include the remote gateway added in step 1.
See Adding an AutoIKE key VPN tunnel
.
Add an incoming encrypt policy with External_All as the source address to allow all dialup users to
access the VPN tunnel.
See Adding an encrypt policy
.
For an example dialup VPN configuration, see Dialup VPN
.
Configuring a VPN Concentrator for hub and spoke VPN
A hub and spoke VPN consists of a VPN Concentrator on a central DFL-1000 NPG (the hub) and two or
more VPN tunnels (the spokes). The spoke VPNs communicate with each other through the hub VPN
Concentrator.
To create a hub and spoke configuration, you must create a VPN Concentrator on the central DFL-1000
NPG. You must configure encrypt policies from each VPN spoke network to the VPN Concentrator
network and to the other VPN spoke networks.
For an example VPN hub and spoke configuration, see Hub and spoke VPN (VPN concentrator)
.
This section describes:
Configuring the VPN Concentrator
Configuring the member VPNs
Configuring the VPN Concentrator
On the VPN Concentrator network, you must create one VPN tunnel for each of the prospective VPN
Concentrator members and then add these tunnels to a VPN concentrator. You can add both AutoIKE
and manual key VPN tunnels to a VPN Concentrator.
Encrypt policies control the direction of traffic through the VPN Concentrator. You must create a separate
encrypt policy for each VPN added to the Concentrator. These policies allow inbound and outbound VPN
connections between the Concentrator and the member VPN tunnels. The encrypt policy for each
member VPN tunnel must include the member VPN tunnel name.
To configure the VPN Concentrator:
Add the required number of remote gateways.
Each AutoIKE key tunnel requires a remote gateway.
See Adding a remote gateway
.
Add the required number of AutoIKE key VPN tunnels and include the remote gateways added in
step 1.
See Adding an AutoIKE key VPN tunnel
.
Add the required number of manual key VPN tunnels.
See Adding a manual key VPN tunnel
.
Add a VPN concentrator that includes the tunnels added in steps 2 and 3.
See Adding a VPN concentrator
.
Add one encrypt policy for each member VPN. Use the following configuration for each policy:
Source
VPN Concentrator address.
Destination
Member VPN address.

Содержание

Скачать