
Chapter 13 VPN 257
Nortel Business Secure Router 252 Configuration — Basics
Table 63 describes the fields in Figure 81.
Table 63 VPN Client Termination advanced
Label Description
NAT Traversal Select Enabled in order to Use NAT traversal when there is a
NAT router between the Business Secure Router and the
Contivity VPN clients.
The Contivity VPN clients must also have NAT traversal enabled.
You also need to specify the UDP port that is used for the VPN
traffic.
Disable Client IKE
Source Port
Switching
With client IKE source port switching, if the Business Secure
Router detects that traffic is going through NAT, it asks the client
to use a UDP port higher than the standard of 500 (such as port
1023). Turn off client source port switching if the NAT router
requires IKE to use port 500.
UDP Port Specifies the UDP port to use for the VPN traffic. In order for a
Contivity VPN client behind a NAT router to receive an initiating
IPSec packet, set the NAT router to forward this UDP port to the
VPN Contivity client behind the NAT router.
Fail-Over The fail-over feature allows a Contivity VPN client to establish a
VPN connection to a backup IPSec router when the Business
Secure Router is not accessible.
The VPN fail-over feature must also be set up in the Contivity
VPN clients.
First Gateway
Second Gateway
Third Gateway
Enter the IP addresses of the backup IPSec routers.
When the Business Secure Router is unreachable or fails to
respond to IKE negotiation, the Contivity VPN client tries to
establish a VPN connection to a backup IPSec router.
Enable Failover
Tuning
Enable the VPN fail-over feature to have the Business Secure
Router keep sending keep-alive packets to the Contivity VPN
clients in order to check the connection and keep the connection
alive.
Interval Specifies how long the VPN Contivity client waits between VPN
connection checks.
Max Number of
Retransmissions
Specifies the maximum number of retransmissions (0~255) of the
keep-alive packets. This is how many times the VPN Contivity
client can resend the keep-alive packet to the Business Secure
Router to check the connection before attempting to use the first
fail-over gateway.
Komentarze do niniejszej Instrukcji