D-Link DFL-1000 [97/168] Hub and spoke vpn vpn concentrator

D-Link DFL-1000 [97/168] Hub and spoke vpn vpn concentrator
DFL-1000 User Manual
9
7
Select OK to save the manual key tunnel.
Repeat steps Select New to add a manual key tunnel.
to Select OK to save the manual key tunnel. on
the appropriate DFL-1000 NPG, using the client information in Example DFL-1000 VPN gateway and
client manual key tunnels.
Adding internal and external addresses
Use the procedure Adding source and destination addresses for a remote client VPN.
Adding an encrypt policy
Use the procedure Adding an encrypt policy for a remote client.
Configuring the IPSec VPN client
The VPN client must be running industry-standard IPSec AutoIKE key VPN client software, such as the
SafeNet/Soft-PK client from SafeNet, Inc.
Configure the client as required to connect to the DFL-1000 VPN gateway using an IPSec VPN
configuration. Use the information in Example DFL-1000 VPN gateway and client manual key tunnels
to
configure the client.
Hub and spoke VPN (VPN concentrator)
Using a VPN concentrator you can create a hub and spoke VPN configuration to direct traffic through a
central DFL-1000 NPG from one VPN tunnel to another VPN tunnel. You create the hub and spoke
configuration by adding a VPN concentrator to the central (or hub) DFL-1000 NPG and then adding VPN
tunnels to the concentrator. Each VPN tunnel provides connectivity to a different remote VPN gateway.
All of the VPN concentrator member tunnels can establish VPN connections with any of the other
member VPN tunnels.
In this example, a company with a main office and two branch offices communicates using a hub and
spoke VPN configuration. The Main Office is the hub where the VPN tunnels terminate, while Branch
Office 1 and Branch Office 2 are the spokes. The Main Office has a VPN tunnel to each branch office.
Branch 1 and Branch 2 each has its own VPN tunnel to the hub.
The Main Office hub needs two encrypt policies, one policy to Branch 1 and one policy to Branch 2. Each
spoke also needs two encrypt policies, one policy to the Main Office (the hub) and one policy to the other
spoke. The two policies at each spoke use the same tunnel. In the policy list for each spoke, the policy to
the hub must be arranged in the policy list above the policy to the other spoke.
Example hub and spoke VPN configuration
shows the example configuration. Each branch office has a
VPN tunnel that terminates at the Main Office, where the DFL-1000 NPG directs the traffic between the
VPN tunnels.

Содержание

Скачать