13.07.2015 Views

Administration of the Avaya G350 Media Gateway - Avaya Support

Administration of the Avaya G350 Media Gateway - Avaya Support

Administration of the Avaya G350 Media Gateway - Avaya Support

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Configuring IPSec VPNFigure 21: Full solution: hub-and-spoke with VPN for data and VoIP control backupWAN link (PPP or FR)IPSec VPN linkPSTNVoIP VLAN(s)<strong>Gateway</strong>WANVoIP bearer +primary control<strong>Avaya</strong> GW<strong>G350</strong>E<strong>the</strong>rnetBranch OfficeData VLAN(s)DSL orCablemodemData + VoIPcontrol backupAccessRouter +VPNterminationCentral OfficeInternetConfiguring hub-and-spoke with VPN for data and VoIP control backupThis section describes how to configure Hub-and-spoke with VPN for data and VoIP controlbackup, followed by a detailed configuration example.To configure Hub-and-spoke with VPN for data and VoIP control backup:1. Configure <strong>the</strong> Branch Office as follows:●●●The default gateway is <strong>the</strong> Internet interface.VPN policy is configured on <strong>the</strong> Internet interface egress as follows:Traffic from <strong>the</strong> local GRE tunnel endpoint to <strong>the</strong> remote GRE tunnel endpoint -> encrypt,using IPSec tunnel mode, with <strong>the</strong> remote peer being <strong>the</strong> Main Office.ACL is configured on <strong>the</strong> Internet interface to allow only <strong>the</strong> VPN tunnel and ICMP traffic,as follows:Ingress:1. IKE (UDP/500) from remote tunnel endpoint to local tunnel endpoint -> Permit2. ESP/AH from remote tunnel endpoint to local tunnel endpoint -> Permit3. Remote GRE tunnel endpoint to local GRE tunnel endpoint -> Permit246 <strong>Administration</strong> <strong>of</strong> <strong>the</strong> <strong>Avaya</strong> <strong>G350</strong> <strong>Media</strong> <strong>Gateway</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!