Ubigate iBG2016 Configuration Guide/Ed.00
© SAMSUNG Electronics Co., Ltd.
257
Remote Access: Mode Configuration
The other method to achieve IPSec remote access in Ubigate iBG2016 is the
mode configuration method.
This method makes the VPN client an extension of the LAN being accessed
by the VPN client. The remote client appears as a network accessing some
resource behind the VPN server.
The VPN client is allocated a private IP address by the VPN server and the
client uses this as the source IP address in the inner IP header in tunnel mode.
In tunnel mode, at each IKE end point, the IP traffic to be protected is
completely encapsulated with another IP packet. In this, the inner IP header
remains the same as seen in the original traffic to be protected. In the outer IP
header, the source and destination addresses are the addresses of the tunnel
end points.
Typically, for a remote user, the source address of the outer IP header is the
dynamic public IP address provided by the ISP. When mode configuration is
enabled, the source address of the inner IP header is the private address
allocated by the VPN server to the VPN client.
As in the case of user group method, the administrator creates an IKE policy
for a logical group of users such as a department in an organization.
The identity information used to identify each user uniquely is configured in
the IKE policy. The IKE policy is attached to a mode configuration record.
The mode configuration record contains an IPSec policy template to be used
for creating dynamic IPSec policy. Also, the record contains one or more pools
of private IP addresses to be used for allocating the addresses to the VPN
clients. Besides the private IP address, the VPN server can also provide WINS
and DNS server addresses.
Upon successful IKE authentication of a VPN client, the server checks
whether the IKE policy used to authenticate the VPN client is enabled for
mode configuration. If so, the server allocates a private IP address from one of
the IP pools in the mode configuration record to the VPN client.
The destination address field in the IPSec template attached to the user group
is filled in with the private IP address allocated to the VPN client and this is
installed as an IPSec policy.
This guide provides information and examples on how to configure IPSec.
Summary of Contents for Ubigate iBG2016
Page 1: ......
Page 16: ...INTRODUCTION XIV SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 34: ......
Page 62: ...CHAPTER 4 System Logging 28 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 70: ......
Page 108: ......
Page 140: ...CHAPTER 4 RIP 104 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 156: ...CHAPTER 6 BGP 120 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 180: ...CHAPTER 8 VRRP 144 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 264: ...CHAPTER 10 QoS 228 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 272: ......
Page 298: ...CHAPTER 3 Firewall NAT 248 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 356: ...CHAPTER 5 IPSEC 306 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 358: ......
Page 744: ...EQBD 000071 Ed 00 ...