cc/td/doc/product/aggr/vpn5000/5000sw/conc52x
hometocprevnextglossaryfeedbacksearchhelp
PDF

Table of Contents

Handling VPN Traffic

Handling VPN Traffic

This chapter describes how to use the Ethernet ports, set an IPsec gateway, and configure a firewall to allow VPN traffic. VPN traffic consists of IPsec packets, but not normal IP traffic, including routing updates.

Placing the Concentrator on the Ethernet Network

You can place the VPN 5001 concentrator behind your firewall using one Ethernet port, or you can place the concentrator in parallel with the firewall, with one port in front and one port behind. The following sections describe how to use each configuration.

Using One Port Inside and One Port Outside the Firewall

When you use both Ethernet ports, Ethernet 1 is a VPN-only port. The VPN-only port accepts secure VPN traffic, so you can place this port in front of the firewall and still maintain security. Ethernet 0 connects to the network behind the firewall, as shown in Figure 4-1.


Figure 4-1: Dual Ethernet Installation


Use a VPN-only port in conjunction with the IPsec gateway, as described in the "Identifying an IPsec Gateway for Ethernet 1" section.


Note   The VPN-only port can respond to certain ICMP requests, such as ping and traceroute.

Using One Port Inside the Firewall

If you do not have a second Ethernet network in front of the firewall, connect Ethernet 0 to the network behind the firewall and leave Ethernet 1 unconnected, as shown in Figure 4-2.


Figure 4-2: Single Ethernet Installation


Identifying an IPsec Gateway for Ethernet 1

Identify the Internet gateway address where you want the concentrator to send all VPN traffic from the VPN-only port, Ethernet 1. This router IP address is called the IPsec gateway and must be on the same subnet as Ethernet 1. You can only specify one IPsec gateway for the concentrator.

Follow these steps to identify the IPsec gateway:

Command Purpose

Step 1 

configure General

Allows you to configure the General section.

Step 2 

IPsecGateway = IP_Address

Where the IP_Address is the router address where you want to send all VPN traffic.

Configuring the Firewall to Allow VPN Packets

If you are using only Ethernet 0 behind a firewall, configure the firewall to allow VPN packets for the following tunnel types:

See the guide that came with your firewall for configuration information.


hometocprevnextglossaryfeedbacksearchhelp
Posted: Wed Sep 27 10:14:24 PDT 2000
Copyright 1989-2000©Cisco Systems Inc.