Digi ConnectPort X4 User's Guide Page 86

  • Download
  • Add to my manuals
  • Print
  • Page
    / 271
  • Table of contents
  • TROUBLESHOOTING
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 85
Configuration through the web interface
86
Example VPN configuration
The diagram shows a Digi Connect WAN VPN used as a primary remote site router:
How VPN tunnels work
The Digi device’s Ethernet port usually connects to a switch or hub, which then connects to other
Ethernet devices. The mobile/cellular carrier provides only one IP address to the mobile interface.
The Digi device uses Network Address Translation (NAT), where only the mobile IP address is
visible to the outside. Private IP addresses are typically used on the remote site LAN connected to
the Digi device’s Ethernet port. All outgoing traffic, except the tunneled VPN traffic, uses the
mobile IP address of the Digi device. Using the example network above, the process for initiating
VPN tunnels works like this:
1 Typically, a host or device on the remote subnet (in this case, 172.17.1.0) requests
information from a host on the main site (HQ) subnet (172.16.5.0). For example, a computer
at 172.17.1.20 needs a file from 172.16.5.100.
2 The Digi device sees the request as being on the HQ subnet and checks whether a VPN
tunnel exists between the two sites.
3 If no tunnel exists, the Digi device initiates a VPN tunnel request to its peer — the VPN
concentrator at HQ. The VPN policy settings are compared, and if they match, an IPsec
tunnel is created between the Digi device and the VPN concentrator. Traffic is encrypted as
defined in the VPN policies.
Cellular
Data Network
Digi
Connect
VPN
Internet
Remote Site HQ
166.123.99.99
209.123.123.123
PWR
OK
WIC0
ACT/CH0
ACT/CH1
WIC0
ACT/CH0
ACT/CH1
ETH
ACT
COL
VPN
Appliance
172.16 .5.0/2 4
17
2.17.1.0
/
24
172.17.1.1
Private IP Tunnel
172.16.5.1
IPSec ESP
WAN
Page view 85
1 2 ... 81 82 83 84 85 86 87 88 89 90 91 ... 270 271

Comments to this Manuals

No comments