13.07.2015 Views

Administration of the Avaya G350 Media Gateway - Avaya Support

Administration of the Avaya G350 Media Gateway - Avaya Support

Administration of the Avaya G350 Media Gateway - Avaya Support

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Typical installationsFigure 20: Hub-and-spoke with hub redundancy/load sharingIPSec VPN linkBranchOffice<strong>Avaya</strong> GW<strong>G350</strong>E<strong>the</strong>rnetDSL orCablemodemInternetAccessRouter +VPNterminationAccessRouter +VPNterminationPrimary MainOfficeBackup MainOfficeConfiguring <strong>the</strong> VPN hub redundancy/load sharing topologiesThis section describes how to configure <strong>the</strong> VPN Hub Redundancy/Load sharing topologies,followed by a detailed configuration example.To configure <strong>the</strong> VPN Hub Redundancy/Load sharing topologies:1. Configure <strong>the</strong> Branch Office as follows:● VPN policy is configured on <strong>the</strong> Internet interface egress as follows:GRE Traffic from <strong>the</strong> local tunnel endpoint to remote tunnel endpoint 1 -> encrypt, usingIPSec tunnel mode, with <strong>the</strong> remote peer being tunnel endpoint 1.●GRE Traffic from <strong>the</strong> local tunnel endpoint to remote tunnel endpoint 2 -> encrypt, usingIPSec tunnel mode, with <strong>the</strong> remote peer being tunnel endpoint 2.ACL is configured on <strong>the</strong> Internet interface to allow only <strong>the</strong> VPN / ICMP traffic, asfollows:Ingress:1. IKE (UDP/500) from remote tunnel endpoints to local tunnel endpoint -> Permit2. ESP/AH from remote tunnel endpoint to local tunnel endpoint -> PermitIssue 3 January 2005 239

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!