13.07.2015 Views

Administration of the Avaya G350 Media Gateway - Avaya Support

Administration of the Avaya G350 Media Gateway - Avaya Support

Administration of the Avaya G350 Media Gateway - Avaya Support

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Typical installationsConfiguring <strong>the</strong> mesh VPN topologyThis section describes how to configure <strong>the</strong> mesh VPN topology, followed by a detailedconfiguration example.To configure <strong>the</strong> mesh VPN topology:1. Configure branch <strong>of</strong>fice 1 as follows:● The default gateway is <strong>the</strong> Internet interface.● VPN policy is configured on <strong>the</strong> Internet interface egress as follows:● Traffic from <strong>the</strong> local subnets to <strong>the</strong> Second Spoke subnets -> encrypt, using tunnelmode IPSec, with <strong>the</strong> remote peer being <strong>the</strong> Second Spoke.●●Traffic from <strong>the</strong> local subnets to anyone -> encrypt, using tunnel mode IPSec,with <strong>the</strong> remote peer being <strong>the</strong> Main Office (VPN hub).ACL is configured on <strong>the</strong> Internet interface to allow only <strong>the</strong> VPN / ICMP traffic, as followsIngress:1. IKE from Main Office IP to Branch IP -> Permit2. ESP from Main Office IP to Branch IP -> Permit3. IKE from Second Branch IP to Branch IP -> Permit4. ESP from Second Branch IP to Branch IP -> Permit5. ICMP from anyone to local tunnel endpoint -> PermitNote: This allows <strong>the</strong> PMTUD application to work.6. All allowed services from anyone to any local subnet -> PermitNote: Due to <strong>the</strong> definition <strong>of</strong> <strong>the</strong> VPN Policy, this will be allowed only if traffic comesover ESP.7. Default -> DenyEgress:1. IKE from Branch IP to Main Office IP -> Permit2. ESP from Branch IP to Main Office IP -> Permit3. IKE from Branch IP to Second Branch IP -> Permit4. ESP from Branch IP to Second Branch IP -> Permit5. ICMP from local tunnel endpoint to anyone -> PermitNote: This allows <strong>the</strong> PMTUD application to work.6. All allowed services from any local subnet to anyone -> PermitNote: This traffic is tunnelled using VPN.7. Default -> DenyIssue 3 January 2005 227

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!