Scenario 1: One-pair VPN Trunk



Similar documents
Based on the VoIP Example 1(Basic Configuration and Registration), we will introduce how to dial the VoIP call through an encrypted VPN tunnel.

How to access peers with different VPN through IPSec. Tunnel

How To Establish Site-to-Site VPN Connection. using Preshared Key. Applicable Version: onwards. Overview. Scenario. Site A Configuration

Using IPsec VPN to provide communication between offices

Cisco - Configure the 1721 Router for VLANs Using a Switch Module (WIC-4ESW)

Workflow Guide. Establish Site-to-Site VPN Connection using RSA Keys. For Customers with Sophos Firewall Document Date: November 2015

Web Authentication Application Note

How to Connect SSTP VPN from Windows Server 2008/Vista to Vigor2950

VPN Configuration of ProSafe VPN Lite software and NETGEAR ProSafe Router:

Tech-Note Bridges Vs Routers Version /06/2009. Bridges Vs Routers

ZyWALL USG-Series. How to setup a Site-to-site VPN connection between two ZyWALL USG series.

Lab 4.4.8a Configure a Cisco GRE over IPSec Tunnel using SDM

VPN PPTP Application. Installation Guide

Figure 41-1 IP Filter Rules

Setting up VPN connection: DI-824VUP+ with Windows PPTP client

Configuring IPsec VPN with a FortiGate and a Cisco ASA

VPN Configuration of ProSafe Client and Netgear ProSafe Router:

Configuring a VPN for Dynamic IP Address Connections

IP Office - Job Aid Small Community Networking

VPN L2TP Application. Installation Guide

Intercommunication between two MyPBX (via VoIP Trunking)

Enabling NAT and Routing in DGW v2.0 June 6, 2012

Chapter 6 Virtual Private Networking

ISG50 Application Note Version 1.0 June, 2011

Workflow Guide. Establish Site-to-Site VPN Connection using Digital Certificates. For Customers with Sophos Firewall Document Date: November 2015

How to setup PPTP VPN connection with DI-804HV or DI-808HV using Windows PPTP client

How to Setup PPTP VPN Between a Windows PPTP Client and the DIR-130.

IPsec VPN Application Guide REV:

Network/VPN Overlap How-To with SonicOS 2.0 Enhanced Updated 9/26/03 SonicWALL,Inc.

Watson SHDSL Router Application Manual

PowerLink Bandwidth Aggregation Redundant WAN Link and VPN Fail-Over Solutions

How To - Configure Virtual Host using FQDN How To Configure Virtual Host using FQDN

Load Balance Mechanism

Configuring IPsec between a Microsoft Windows XP Professional (1 NIC) and the VPN router

Enable VPN PPTP Server Function

Network Address Translation (NAT)

Copyright ZYCOO All Rights Reserved 1 / 8

How To Establish IPSec VPN connection between Cyberoam and Mikrotik router

V310 Support Note Version 1.0 November, 2011

VPN Wizard Default Settings and General Information

NAT (Network Address Translation)

How To Establish IPSec VPN between Cyberoam and Microsoft Azure

Configuration Guide. How to set up the IPSec site-to-site Tunnel between the D-Link DSR Router and the Sonicwall Firewall.

Establishing a VPN tunnel to CNet CWR-854 VPN router using WinXP IPSec client

How To Configure L2TP VPN Connection for MAC OS X client

Session Title: Exploring Packet Tracer v5.3 IP Telephony & CME. Scenario

How To - Setup Cyberoam VPN Client to connect to a Cyberoam for the remote access using preshared key

How To Set Up A Vpn Tunnel Between Winxp And Zwall On A Pc 2 And Winxp On A Windows Xp 2 On A Microsoft Gbk2 (Windows) On A Macbook 2 (Windows 2) On An Ip

7. Configuring IPSec VPNs

Peer-to-Peer SIP Mode with FXS and FXO Gateways

Optimum Business SIP Trunk Set-up Guide

Configuration Guide. How to Configure SSL VPN Features in DSR Series. Overview

Configure IPSec VPN Tunnels With the Wizard

Version : 2.0 Date : 2006/6/12

Configuring a FortiGate unit as an L2TP/IPsec server

Overview. Author: Seth Scardefield Updated 11/11/2013

Configuring an IPsec VPN to provide ios devices with secure, remote access to the network

Connecting an Android to a FortiGate with SSL VPN

I. What is VPN? II. Types of VPN connection. There are two types of VPN connection:

How To Setup Cyberoam VPN Client to connect a Cyberoam for remote access using preshared key

Edgewater Routers User Guide

Interconnecting Cisco Networking Devices: Accelerated (CCNAX) 2.0(80 Hs) 1-Interconnecting Cisco Networking Devices Part 1 (40 Hs)

VPN. VPN For BIPAC 741/743GE

Configuring TheGreenBow VPN Client with a TP-LINK VPN Router

How To Configure SSL VPN in Cyberoam

Configuration Guide. How to set up the IPSec site-to-site Tunnel between the D-Link DSR Router and the Cisco Firewall. Overview

Chapter 9 Monitoring System Performance

VPN Tracker for Mac OS X

Configuring IPSec VPN Tunnel between NetScreen Remote Client and RN300

Virtual Server in SP883

Edgewater Routers User Guide

VLAN 802.1Q. 1. VLAN Overview. 1. VLAN Overview. 2. VLAN Trunk. 3. Why use VLANs? 4. LAN to LAN communication. 5. Management port

DFL-210/260, DFL-800/860, DFL-1600/2500 How to setup IPSec VPN connection

Title: Peer to Peer Communications on TDE systems Using Multi-Tech Routers

Firewall Defaults and Some Basic Rules

Digi Connect WAN Application Helper NAT, GRE, ESP and TCP/UPD Forwarding and IP Filtering

Multi-Homing Dual WAN Firewall Router

Chapter 5 Virtual Private Networking Using IPsec

Chapter 4 Virtual Private Networking

Firewall VPN Router. Quick Installation Guide M73-APO09-380

Connecting Remote Offices by Setting Up VPN Tunnels

Abstract. Avaya Solution & Interoperability Test Lab

Linking 2 Sites Together Using VPN How To

Configuration Guide. How to set up the IPSec site-to-site Tunnel between the D-Link DSR Router and the Fortinet Firewall. Overview

Using SonicWALL NetExtender to Access FTP Servers

A. Hot-Standby mode and Active-Standby mode in High Availability

Table Example 1-basic settings in Vigor 3300V and 2900V. WAN IP Port Number Phone Number Proxy Codec

How to configure VPN function on TP-LINK Routers

Virtual Private Network and Remote Access Setup

1 PC to WX64 direction connection with crossover cable or hub/switch

: Interconnecting Cisco Networking Devices Part 1 v2.0 (ICND1)

UTM - VPN: Configuring a Site to Site VPN Policy using Main Mode (Static IP address on both sites) i...

How To Configure An Ipsec Tunnel On A Network With A Network Gateways (Dfl-800) On A Pnet 2.5V2.5 (Dlf-600) On An Ipse Vpn

VPN Configuration Guide. Cisco Small Business (Linksys) WRV210

Netgear ProSafe VPN firewall (FVS318 or FVM318) to Cisco PIX firewall

VPN Configuration Guide. Cisco Small Business (Linksys) RV016 / RV042 / RV082

VPN Configuration Guide. Cisco Small Business (Linksys) WRVS4400N / RVS4000

Application Notes. How to Configure UTM with Apple OSX and ios Devices for IPsec VPN

Configuring Network Address Translation (NAT)

Setting up D-Link VPN Client to VPN Routers

Transcription:

VPN Trunk Load-Balance between Vigor3200 and Other Vigor Router This section will discuss how to build VPN Trunk with load-balance between Vigor3200 and other router (e.g., Vigor3300). Scenario 1: One-pair VPN Trunk The purpose is to setup a VPN trunk between Vigor3200 (192.168.1.0/24) and Vigor3300 (192.168.33.0/24). At present, Vigor3200 just supports one VPN trunk group with two members for the same VPN network pair. In this case, the VPN trunk is built for 192.168.1.0/24 <-> 192.168.33.0/24. In other word, although Vigor3200 supports 4 WAN connections, it just allows you to use 2 VPN connections over two WAN ports for one VPN trunk group between the networks 192.168.1.0/24 and 192.168.33.0/24. Note: You can still setup two VPN trunk groups over 4 WAN connections between the networks 192.168.1.0/24 and 192.168.33.0/24. But the VPN traffic can just pass through one VPN trunk group. You can create arbitrary number of VPN trunk groups between Vigor3200 and Vigor3300 for different VPN network pairs. For example, suppose there is another network (192.168.10.0/24) behind Vigor3300. You may create a VPN trunk group over WAN1 and WAN2 connections for 192.168.1.0/24 <-> 192.168.33.0/24, and the other VPN trunk group over WAN3 and WAN4 for 192.168.1.0/24 <-> 192.168.10.0/24. Please refer to the Scenario 2 described in this document later. Vigor3200 as a VPN client (dial out site), LAN: 192.168.1.0/24 WAN 1 IP: 202.211.110.30 (My GRE IP, 10.0.0.1, Peer GRE IP, 10.0.0.2) WAN 2 IP: 202.211.120.30 (My GRE IP, 10.0.0.3, Peer GRE IP, 10.0.0.4) Vigor3300 as a VPN server (dial in site), LAN: 192.168.33.0/24 WAN 1 IP: 202.211.110.100 (Local GRE IP, 10.0.0.2, Remote GRE IP, 10.0.0.1) WAN 2 IP: 202.211.120.100 (Local GRE IP, 10.0.0.4, Remote GRE IP, 10.0.0.3) 1

Settings for Vigor 3200: 1. Open VPN and Remote Access>>>LAN to LAN. Choose Index number 1 for configuring a VPN LAN to LAN profile. 2. In the following page, please configure the settings as the following figure. 2

3. Click OK to save the configuration and return to previous page. Choose Index number 2 for configuring another VPN LAN to LAN profile. 4. In this page, please configure the settings as the following figure. 3

5. Click OK to save the configuration. 6. Open VPN and Remote Access>>VPN TRUNK Management. Add these VPN profiles to the VPN Trunk and set Load Balance as the Attribute Mode. 7. Click Advanced for specifying Load Balance Algorithm. 4

8. When the VPN trunk is successfully connected, you may check the connection status by viewing the page of VPN and Remote Access>>Connection Management. Transferred packets (Tx Pkts) will keep increasing through both tunnels when outgoing packets sent to the remote VPN network. Settings for Vigor3300: 1. Open VPN>>IPSec>>VPN Trunk>>Policy Table. Choose Index 1 and click Edit. 5

2. In this page, please configure the settings as the following figure. 3. Click Apply to save the configuration and return to previous page. Choose Index 2 for configuring another VPN Trunk policy. 4. In this page, please configure the settings as the following figure. 6

5. Click Apply to save the configuration. 6. Open VPN>>VPN Trunk>>Group Table to group these two VPN policies. 7. Choose Index 1 and click Edit. Add these two VPN profiles (wan1 and wan2) to a VPN Trunk. Now, one-pair VPN trunk between Vigor3200 (192.168.1.0/24) and Vigor3300 (192.168.33.0/24) has be established. 7

Scenario 2: Two-pair VPN Trunk Vigor3200 as VPN client (dial out site) LAN: 192.168.1.0/24 WAN 1 IP: 202.211.110.30 (My GRE IP, 10.0.0.1, Peer GRE IP, 10.0.0.2) WAN 2 IP: 202.211.120.30 (My GRE IP, 10.0.0.3, Peer GRE IP, 10.0.0.4) WAN 3 IP: 202.211.130.30 (My GRE IP, 10.0.0.5, Peer GRE IP, 10.0.0.6) WAN 4 IP: 202.211.140.30 (My GRE IP, 10.0.0.7, Peer GRE IP, 10.0.0.8) Vigor3300 as VPN server (dial in site), LAN1: 192.168.33.0/24 LAN2: 192.168.10.0/24 WAN 1 IP: 202.211.110.100 (Local GRE IP, 10.0.0.2, Remote GRE IP, 10.0.0.1) WAN 2 IP: 202.211.120.100 (Local GRE IP, 10.0.0.4, Remote GRE IP, 10.0.0.3) WAN 3 IP: 202.211.130.100 (Local GRE IP, 10.0.0.6, Remote GRE IP, 10.0.0.5) WAN 4 IP: 202.211.140.100 (Local GRE IP, 10.0.0.8, Remote GRE IP, 10.0.0.7) Settings for Vigor 3200: 1. Open VPN and Remote Access>>>LAN to LAN. 2. Create LAN to LAN profile 1-4. Setting configuration is the same as Scenario 1. The differences are, Remote Network IP of Profile 1 and Profile 2 must be 192.168.33.0/24 and Remote Network IP of Profile 3 and Profile 4 must be 192.168.10.0/24. 8

3. Open VPN and Remote Access>>VPN TRUNK Management. Add these VPN profiles to the VPN Trunk and set Load Balance as the Attribute Mode. Setting configuration is the same as Scenario 1. Profile 1 and Profile 2 are one pair; Profile 3 and Profile 4 are the other pair. 4. When the VPN trunk is successfully connected, you may check the connection status by viewing the page of VPN and Remote Access>>Connection Management. Transferred packets (Tx Pkts) will keep increasing through both tunnels when outgoing packets sent to the remote VPN network. 9

Settings for Vigor3300: 1. Open Advanced>>LAN VLAN. Choose the tab of 802.1Q VLAN. Configure the settings as the following figure. 2. Next, open Network>>LAN. Set two LAN subnet: LAN1 192.168.33.0/24 and LAN2 192.168.10.0/24. 3. Click Apply. 4. Open VPN>>IPSec>>VPN Trunk>>Policy Table to create VPN Trunk policy. 10

The way to configure the setting is the same as Scenario 1. 5. Open VPN>>VPN Trunk>>Group Table to group these VPN policies. Group two VPN policies as the following figure and then click Apply. The way to configure the setting is the same as Scenario 1. Now, two-pair VPN trunk between Vigor3200 (192.168.1.0/24) and Vigor3300 (192.168.33.0/24) has be established. 11