Page 256 / 342 Scroll up to view Page 251 - 255
14
Viewing Reports
256
Nokia IP45 Security Platform User’s Guide v4.0
Page 257 / 342
Nokia IP45 Security Platform User’s Guide v4.0
257
15
Working with VPNs
This chapter describes how to use Nokia IP45 as a VPN client, server or gateway. It includes the
following topics:
±
About VPN
±
Setting Up the Nokia IP45 Security Platform as a VPN Server
±
Configuring Remote Access VPNs
±
Nokia Satellite X to Nokia Satellite X (VPN Gateway-to-Gateway)
±
VPN Scenarios
±
VPN Routing Between two Nokia IP45 Security Platforms
±
Nokia IP45 Tele 8 to Check Point FP1, FP2, FP3, NG, NG AI, NGX R60 or NGX R61
±
Nokia IP45 Tele 8 to Check Point NG AI
±
Configuring Route-Based VPNs
About VPN
In addition to a full firewall functionality, Nokia IP45 Tele 8, and Nokia Satellite X enable
secure telecommuter access from home to the office network through the virtual private network
(VPN) functionality.
VPN consists of at least one VPN server or gateway, and several VPN clients. A VPN server
makes the corporate network remotely available to authorized users, such as employees working
from home, who connect to the VPN server by using VPN clients. A VPN gateway can be
connected to another VPN gateway in a permanent, bidirectional relationship. The two
connected networks function as a single network.
A connection between two VPN sites is called a VPN tunnel. VPN tunnels encrypt and
authenticate all traffic passing through them. Through these tunnels, you can safely use your
company network resources when you work at home. For example, you can securely read email,
use your company intranet, or access your company database from home.
Nokia IP45 Tele 8, and Satellite 16/32/U licenses provide VPN functionality. Nokia IP45 Tele 8
contains a VPN client and can act as a VPN server. Nokia IP45 Satellite 16/32/U can act as a
VPN client, a VPN server, or a VPN gateway.
Both Nokia IP45 Tele 8, and Nokia IP45 Satellite X enables a number of solutions to support
your VPN connectivity needs that are explained in the following sections.
Page 258 / 342
15
Working with VPNs
258
Nokia IP45 Security Platform User’s Guide v4.0
Figure 11
VPN Topologies
Table 56
VPN Topologies
VPN Client
Gateway
SecuRemote, R55/R56 VPN
Client
Nokia IP45 Satellite
Nokia IP45 Tele
Nokia IP45 Satellite
Nokia IP45 Tele
Check Point NG AI, NG, FP3, FP2, FP1
Nokia IP45 Tele
Check Point NG AI using VPN-1 Edge/
Embedded Gateway (RAS Community)
Nokia IP45 Satellite (gateway)
Nokia IP45 Satellite (gateway)
Nokia IP45 Satellite (gateway)
Check Point NG AI, NG, FP3, FP2, FP1
Nokia IP45 Satellite
Check Point NG AI using VPN-1 Edge/
Embedded Gateway Check Point Smart
LSM using VPN-1 Edge/Embedded ROBO
gateway.
SecuRemote
Check Point NG AI/NG/FP1/FP2/
VPN-1Edge/Embedded Gateway
(RAS community)
Check Point Smart LSM (VPN-1Edge/Embedded
ROBO Gateway)
Check Point NG AI/NG/FP1/FP2/FP3 (DAIP)
VPN-1Edge/Embedded Gateway (Star VPN community)
Windows 2000 (server and host)
VPN clients
VPN gateway
IP45 Tele
IP45 Satellite
IP45 Satellite
VPN-1 Gateway
Page 259 / 342
Setting Up the Nokia IP45 Security Platform as a VPN Server
Nokia IP45 Security Platform User’s Guide v4.0
259
Setting Up the Nokia IP45 Security Platform as a VPN
Server
Using the Nokia IP45 security platform, you can make your network remotely available to
authorized users by setting up your Nokia IP45 as a VPN server. Remote access users can
connect to the VPN server through Check Point SecuRemote or a Nokia IP45 VPN client in
remote access VPN mode.
IP45 includes an integrated L2TP IPSec VPN Server. Layer 2 Tunneling Protocol (L2TP) is a
tunneling protocol that supports remote access virtual private networks. When this server is
enabled, IP45 appliance can provide secure remote access to desktop or mobile clients running a
Microsoft Windows L2TP IPSec VPN.
IP45 Tele and Satellite both provide VPN functionality. Nokia IP45 Tele license contains a VPN
client and can act as a VPN server. Nokia IP45 satellite can act as a VPN client, a VPN server, or
a VPN gateway.
To set up the IP45 device as a SecuRemote VPN server
1.
Choose VPN from the IP45 main menu.
The SecuRemote VPN Server page opens.
.
2.
Click Allow the SecuRemote users to connect from the Internet.
Nokia IP45 Satellite
Check Point NG AI using VPN-1 Edge/
Embedded Gateway (Star Community)
Nokia IP45 Satellite
Windows 2000, Nokia CryptoCluster
series, CISCO PIX
Table 56
VPN Topologies (
continued
)
VPN Client
Gateway
Page 260 / 342
15
Working with VPNs
260
Nokia IP45 Security Platform User’s Guide v4.0
The following page opens.
3.
To allow authenticated users connecting from the Internet to bypass NAT when connecting
to your internal network, click Bypass NAT check box.
4.
To allow authenticated users connecting from the Internet to bypass the firewall and access
your internal network without restriction, click Bypass default firewall policy check box.
5.
Click Apply.
Note
To allow authenticated users to bypass NAT and access your internal network without
restriction, select Bypass NAT. To bypass the firewall, select Bypass default firewall
policy.
To allow L2TP clients to connect
1.
From the main menu, choose VPN.
Remote Access VPN Server page opens.
2.
Check Allow L2TP clients to connect check box.
L2TP options get displayed as shown in the following page:

Rate

3.5 / 5 based on 2 votes.

Popular Nokia Models

Bookmark Our Site

Press Ctrl + D to add this site to your favorites!

Share
Top