Cisco Small Business RV 120W Wireless-N VPN Firewall ...

Cisco Small Business RV 120W Wireless-N VPN Firewall ... Cisco Small Business RV 120W Wireless-N VPN Firewall ...

ipland.com.ua
from ipland.com.ua More from this publisher
12.07.2015 Views

Configuring Virtual Private Networks (VPNs) and SecurityConfiguring Advanced VPN Parameters5• Auto Policy—Some parameters for the VPN tunnel are generatedautomatically. This requires using the IKE (Internet Key Exchange) protocolto perform negotiations between the two VPN Endpoints.• Manual Policy—All settings (including the keys) for the VPN tunnel aremanually input for each end point. No third-party server or organization isinvolved.To create an Auto VPN Policy, you need to first create an IKE policy and then addthe corresponding Auto Policy for that IKE Policy. (See Auto Policy Parameters,page 102.)STEP 5STEP 6In the Remote Endpoint field, select the type of identifier that you want to providefor the gateway at the remote endpoint: IP Address or FQDN (Fully QualifiedDomain Name).In the NetBIOS field, check the Enable box to allow NetBIOS broadcasts to travelover the VPN tunnel, or uncheck this box to disable NetBIOS broadcasts over theVPN tunnel. For client policies, the NetBIOS feature is available by default.Local Traffic Selection and Remote Traffic SectionSTEP 1For both of these sections, configure the following settings:• Local/Remote IP—Select the type of identifier that you want to provide forthe endpoint:- Any—Specifies that the policy is for traffic from the given end point(local or remote). Note that selecting Any for both local and remote endpoints is not valid.- Single—Limits the policy to one host. Enter the IP address of the hostthat will be part of the VPN in Start IP Address field.- Range—Allows computers within an IP address range to connect to theVPN. Enter the Start IP Address and End IP Address in the providedfields.- Subnet—Allows an entire subnet to connect to the VPN. Enter thenetwork address in the Start IP Address field, and enter the SubnetMask in the Subnet Mask field.STEP 2In the Start Address field, enter the first IP address in the range. If you selectedSingle, enter the single IP address in this field and leave the End IP Address fieldblank.Cisco RV120W Administration Guide 99

Configuring Virtual Private Networks (VPNs) and SecurityConfiguring Advanced VPN Parameters5STEP 3STEP 4In the End Address field, enter the last IP address in the range.If you chose Subnet as the type, enter the Subnet Mask of the network.Split DNSSplit DNS allows the Cisco RV120W to find the DNS server of the remote routerwithout going through the ISP (Internet).To enable split DNS:STEP 1STEP 2STEP 3STEP 4STEP 5Check the Enable box.In the Domain Name Server 1 field, specify a Domain Name server IP address,which is used only to resolve the domain configured in the Domain Name 1 field.In the Domain Name Server 2 field, specify a Domain Name server IP address,which is used only to resolve the domain configured in the Domain Name 2 field.In the Domain Name 1 field, specify a domain name, which will be queried onlyusing the DNS server configured in the Domain Name Server 1 field.In the Domain Name 2 field, specify a domain name, which will be queried onlyusing the DNS server configured in the Domain Name Server 2 field.NOTEMake sure that you avoid using overlapping subnets for remote or local trafficselectors. Using these subnets would require adding static routes on the router andthe hosts to be used.For example, a combination to avoid would be:Local Traffic Selector: 192.168.1.0/24Remote Traffic Selector: 192.168.0.0/16Cisco RV120W Administration Guide 100

Configuring Virtual Private Networks (<strong>VPN</strong>s) and SecurityConfiguring Advanced <strong>VPN</strong> Parameters5STEP 3STEP 4In the End Address field, enter the last IP address in the range.If you chose Subnet as the type, enter the Subnet Mask of the network.Split DNSSplit DNS allows the <strong>Cisco</strong> <strong>RV</strong><strong>120W</strong> to find the DNS server of the remote routerwithout going through the ISP (Internet).To enable split DNS:STEP 1STEP 2STEP 3STEP 4STEP 5Check the Enable box.In the Domain Name Server 1 field, specify a Domain Name server IP address,which is used only to resolve the domain configured in the Domain Name 1 field.In the Domain Name Server 2 field, specify a Domain Name server IP address,which is used only to resolve the domain configured in the Domain Name 2 field.In the Domain Name 1 field, specify a domain name, which will be queried onlyusing the DNS server configured in the Domain Name Server 1 field.In the Domain Name 2 field, specify a domain name, which will be queried onlyusing the DNS server configured in the Domain Name Server 2 field.NOTEMake sure that you avoid using overlapping subnets for remote or local trafficselectors. Using these subnets would require adding static routes on the router andthe hosts to be used.For example, a combination to avoid would be:Local Traffic Selector: 192.168.1.0/24Remote Traffic Selector: 192.168.0.0/16<strong>Cisco</strong> <strong>RV</strong><strong>120W</strong> Administration Guide 100

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!