IPSec User Guide2120028Rev 2.2
Introducing IPSecRev 2.2 Jun.11 3ScenariosSierraWirelessAirLinkmodemswithIPSecaredesignedtosupportthegateway‐to‐gatewaysecuritymodel.I
IPsec User Guide4 2120028Figure 1-3: Corporate Email Server scenarioc. Google(twowaytransmissionofinsecuredata):Thelaptopuserwantstoacce
Introducing IPSecRev 2.2 Jun.11 5Figure 1-5: Pass through mode Thenextchapterwalksyouthroughtheinstallationandconfigurationstepsofesta
IPsec User Guide6 2120028
Rev 2.2 Jun.11 622: Installation and Configuration• Set-Up• Installation• Configuration Settings Thischaptercoversinstallationandconfiguration
IPsec User Guide7 2120028Set-UpIPSechasawidevarietyofuserconfigurationoptions.WhenIPSecisenabled,itmustbedoneforthepurposeofcrea
IPsec User Guide8 2120028InstallationPleaseuninstallanypreviousversionsofAceManagerthathadbeeninstalledonyourPC,priortoinstallingthe
IPsec User Guide9 2120028Figure 2-3: IPSec Pane in AceManager2. Click on IPSecThedesiredgrouptabwillshowrespectiveparametersanddetailsont
IPsec User Guide10 2120028IPSec Gateway 64.163.70.30 Fill in the IPSec of the VPN concentrator.Pre-shared Key 1 SierraWireless 8 to 31 case sensitive
IPsec User Guide11 2120028Remote Address 10.11.12.0 Address of the remote device. Choose from two options: 5- Single Address and 17-Subnet Address.Re
IPsec User Guide12 2120028Toconfirmasuccessfulconnection,thefollowingtestscanberun:• ConnectaPCtothemodemandattempttopingtheIPa
IPsec User Guide13 2120028m. Outgoing Host Out of Band:ToaccessinternetbybypassingtheIPSectunnel,youcansetthisparameteras“1”.Note: I
IPsec User Guide14 2120028Figure 2-5: PinPoint Configuration2. Providethe Server IP Addressontheright‐handsidepane.3. EntertheReport Interv
IPsec User Guide15 2120028AnAVLApplicationservermodemreportnotificationimageisprovidedasanexample.Figure 2-6: Application Server Tunnel7
Installation and ConfigurationRev 2.2 Jun.11 16Figure 2-8: Host Private Subnet 3. Clickon PPP ethernet.Setthemodemtoprivatemode.Figure 2-9:
IPsec User Guide17 21200284. Configurethe IPSec Interface parameteras“1”,toenableIPSec.OnceIPSecisenabled,thefactorydefaultsettingssho
Rev 2.2 Jun.11 18AA: Sample Configuration File VPN Configuration fileTwoexamplesofStaticIPandDynamicIPareprovidedinthefollowingsections
IPsec User Guide19 username progent privilege 15 password 0 progent!crypto isakmp policy 2 encr 3des authentication pre-share group 2 lifetime 28000c
Sample Configuration FileRev 2.2 Jun.11 20interface FastEthernet0/1 ip address 192.168.2.1 255.255.255.0 ip nat inside ip virtual-reassembly duplex
IPsec User Guide21 Dynamic IP1841b_dynamic#1841b_dynamic#sh runBuilding configuration...Current configuration : 1479 bytes!version 12.4service timest
Rev 2.2 Jun.11 iImportant Notice Duetothenatureofwirelesscommunications,transmissionandreceptionofdatacanneverbeguaranteed.Datamay
Sample Configuration FileRev 2.2 Jun.11 22!crypto isakmp policy 100 encr 3des authentication pre-share group 2 lifetime 28000crypto isakmp key 6 key
IPsec User Guide23 ip route 0.0.0.0 0.0.0.0 64.163.70.1!ip http serverno ip http secure-serverip nat pool nat 64.163.70.104 64.163.70.104 netmask 255
Rev 2.2 Jun.11 24BB: IPsec Architecture Standards of the M2M IPSec Support SierraWirelessM2MIPSecsupportsthefollowi ngstandards:• RFC1829–
IPsec User Guide25 · MODP4096(available,butnotcurrentlysupported)· MODP6144(available,butnotcurrentlysupported)· MODP8192(available,
Rev 2.2 Jun.11 iiDIRECT,INDIRECT,SPECIAL,GENERAL,INCIDENTAL,CONSEQUENTIAL,PUNITIVEOREXEMPLARYDAMAGESINCLUDING,BUTNOTLIMITEDTO,LOSSO
Rev 2.2 Jun.11 iiiConsultourwebsiteforup‐to‐dateproductdescriptions,documentation,applicationnotes,firmwareupgrades,trouble‐shootingti
Rev 2.2 Jun.11 1ContentsIntroducing IPSec . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
IPsec User Guide2 2120028
Rev 2.2 Jun.11 111: Introducing IPSec• Overview• Scenarios IPprotocolthatdrivestheInternetisinherentlyinsecure.InternetProtocolSecurity
IPsec User Guide2 2120028otherend.TheremotegatewayisconnectedtoaRemotenetworkandtheVPNisconnectedtotheLocalnetwork.Thecommunicat
Comments to this Manuals