
Chapter 68 Virtual Private Networks (VPN) 659
BCM 4.0 Networking Configuration Guide
Example 2
BCM 1 has been configured with a WAN1 address of 10.200.40.12 and a LAN1 address of
10.10.10.1. Your computer at home has the address of 207.44.126.81. An IPSec Remote User
tunnel has been configured on BCM1. This tunnel will obtain it’s IP Address from an IPSec
Address Pool. This IPSec Address Pool is configured with range: 10.10.10.100 - 10.10.10.200
with a subnet mask of 255.255.255.0. You only allow ESP as the IPSec protocol. Firewall is
enabled on LAN1.You will need the following rules:
Table 170 Rule 2
Protocol IPSEC_ESP
Source IP IP Address of client PC (or 0.0.0.0 if not known)
Source Mask 255.255.255.255 (or 0.0.0.0 if not known)
Destination IP IP Address of Interface that will receive VPN Client Connection request for client PC
Destination Mask 255.255.255.255
Table 171 Rule 3
Protocol IPSEC_AH
Source IP IP Address of client PC (or 0.0.0.0 if not known)
Source Mask 255.255.255.255 (or 0.0.0.0 if not known)
Destination IP IP Address of Interface that will receive VPN Client Connection request for client PC.
Destination mask 255.255.255.255
Table 172 Rule 4
Protocol IGNORE
Source IP IP Address from private network assigned to VPN client (or network address if IP
Address Pool used).
Source Mask 255.255.255.255 (or Subnet Mask assigned if IP Address Pool used)
Destination IP IP Network Address of Private network
Destination Mask Subnet Mask of Private network
Commentaires sur ces manuels