Manuale d’uso / di manutenzione del prodotto VPN del fabbricante Allied Telesis
Vai alla pagina of 29
C613-16004-00 REV D www .alliedtelesis.com AlliedW ar e TM OS How T o | Intr oduction This document descri bes how to pr ovide secur e remote acce ss through IP se curity (IPSec) Virtual Priva te Networks (VPN).
Which pr oducts and releases do es it apply to? > Page 2 | AlliedW are™ OS Ho w T o Note: VPNs with Windo ws 2000 clients, without NA T -T This document describes h ow to configure the Windows system to use IPSec VPN to connect to your office through the AR4 1 5S r outer .
Security issue > Page 3 | AlliedW are™ OS Ho w T o Note: VPNs with Windo ws 2000 clients, without NA T -T Security issue Since this Windows VPN solution is usually used to allow remote access int.
Configuring the r outer > P erform in itial sec urity configuration on the router Page 4 | AlliedW are™ OS Ho w T o Note: VPNs with Windo ws 2000 clients, without NA T -T Configuring the r outer .
Configuring the r outer > The configuration script Page 5 | AlliedW are™ OS Ho w T o Note: VPNs with Windo ws 2000 clients, without NA T -T The configuration script Note: Comments are indi cated in the script below using the # symbol.
Configuring the r outer > The configuration script Page 6 | AlliedW are™ OS Ho w T o Note: VPNs with Windo ws 2000 clients, without NA T -T # Firewall enable fire create fire poli=main create fir.
Configuring the router > Set the r outer to use the configuration Page 7 | AlliedW are™ OS Ho w T o Note: VPNs with Windo ws 2000 clients, without NA T -T Set the r outer to use the configuration After loading the configuration onto the switch, set the router to use the script after a reboot.
Configuring the VPN c lient > Add a ne w registry entr y Page 8 | AlliedW are™ OS Ho w T o Note: VPNs with Windo ws 2000 clients, without NA T -T Configuring the VPN client Configuring the Wi ndo.
Configuring the VPN client > Add the IP Security Policy Managem ent snap-in Page 9 | AlliedW are™ OS Ho w T o Note: VPNs with Windo ws 2000 clients, without NA T -T Add the IP Security P olicy Manag ement snap-in Note: Y ou need to know the public IP ad dress for the r outer from y our Internet Ser vice Pr ovider (ISP) for this configuration.
Configuring the VPN client > Add the IP Security Policy Managem ent snap-in Page 10 | AlliedW are™ OS Ho w T o Note: VPNs with Windo ws 2000 clients, without NA T -T 3.
Configuring the VPN client > Create an IP Security Pol icy Page 11 | AlliedW are™ OS Ho w T o Note: VPNs with Windo ws 2000 clients, without NA T -T Cr eate an IP Security P olicy 1. On the Console window , click , then right-click I P Security Policies on Local Mac hine .
Configuring the VPN client > Create an IP Security Pol icy Page 12 | AlliedW are™ OS Ho w T o Note: VPNs with Windo ws 2000 clients, without NA T -T 3. Click Next , then enter a name for y our security po licy (e .g. “T o Head Office”), as shown in the follo wing figure.
Configuring the VPN client > Create an IP Securi ty Rule Page 13 | AlliedW are™ OS Ho w T o Note: VPNs with Windo ws 2000 clients, without NA T -T 5. Click Next. Y ou ha ve now completed the IP Security P olicy Wizard, as sho wn in the following figure.
Configuring the VPN client > Create an IP Securi ty Rule Page 14 | AlliedW are™ OS Ho w T o Note: VPNs with Windo ws 2000 clients, without NA T -T 2. Click Add . This opens the Security Rule Wizard , as shown in the f ollowing figure. 3. Click Next .
Configuring the VPN client > Create an IP Securi ty Rule Page 15 | AlliedW are™ OS Ho w T o Note: VPNs with Windo ws 2000 clients, without NA T -T 4. Click Next . The next window lets y ou specify the network type the IP Security rule applies to .
Configuring the VPN client > Create an IP Filter Page 16 | AlliedW are™ OS Ho w T o Note: VPNs with Windo ws 2000 clients, without NA T -T Cr eate an IP Filter 1. Click Next . The next window , shown in the following figur e , lets you specify the IP filter for the type of IP traffic the IP Secu rity rule applies to .
Configuring the VPN client > Create an IP Filter Page 17 | AlliedW are™ OS Ho w T o Note: VPNs with Windo ws 2000 clients, without NA T -T 3. Click Add . This star ts the IP Filter Wizard , as shown in the following figure. 4. Click Next . This opens the IP T raff ic Source window .
Configuring the VPN client > Create an IP Filter Page 18 | AlliedW are™ OS Ho w T o Note: VPNs with Windo ws 2000 clients, without NA T -T 5. Click Next . This opens the IP T raff ic Destination window . Select A specif ic IP Address fr om the Destination address dr op-down bo x, as shown in the follo wing figure.
Configuring the VPN client > Create an IP Filter Page 19 | AlliedW are™ OS Ho w T o Note: VPNs with Windo ws 2000 clients, without NA T -T 7. Click Next . This opens the IP Protocol Port window . Sele ct Fro m t h is po r t and enter 1 70 1 , as shown in the following figur e .
Configuring the VPN client > Create an IP Filter Page 20 | AlliedW are™ OS Ho w T o Note: VPNs with Windo ws 2000 clients, without NA T -T 9. Click Finish , then on the IP Filter Li st window , click Close . This r eturns you to the Secur ity Rule Wizard IP Filter List windo w .
Configuring the VPN client > Create an IP Filter Page 21 | AlliedW are™ OS Ho w T o Note: VPNs with Windo ws 2000 clients, without NA T -T 11. Click Next . This completes the Rule wizar d. Leav e the Edit properties box uncheck ed, as sho wn in the following figur e .
Configuring the VPN client > Create an IP Filter Page 22 | AlliedW are™ OS Ho w T o Note: VPNs with Windo ws 2000 clients, without NA T -T 13. Click and then right-click on T o Head Office , and select Assign .
Configuring the VPN client > Configure the connection Page 23 | AlliedW are™ OS Ho w T o Note: VPNs with Windo ws 2000 clients, without NA T -T Configur e the connection 1. On your desktop , click Star t > Settings > Control P anel . 2. Double-click the Network and Dial-Up Connection fold er .
Configuring the VPN client > Configure the connection Page 24 | AlliedW are™ OS Ho w T o Note: VPNs with Windo ws 2000 clients, without NA T -T 5. Click Next . The next window lets you assign an associated dialled call or select Do not dial the initial connection .
Configuring the VPN client > Configure the connection Page 25 | AlliedW are™ OS Ho w T o Note: VPNs with Windo ws 2000 clients, without NA T -T 7. Click Next . This opens the Connection Availability window . Select Only for m yself , as shown in the follo wing figure.
Configuring the VPN client > Configure the connection Page 26 | AlliedW are™ OS Ho w T o Note: VPNs with Windo ws 2000 clients, without NA T -T 9. Click Finish . This opens the Connection Window . Enter y our user name and passw ord as shown in the following figur e .
Configuring the VPN client > Configure the connection Page 27 | AlliedW are™ OS Ho w T o Note: VPNs with Windo ws 2000 clients, without NA T -T 11. Click OK . This completes the configuration of the L2TP client. T o connect to the office, click Connect .
T esting the tunnel > Checking the connection from the Windows client Page 28 | AlliedW are™ OS Ho w T o Note: VPNs with Windo ws 2000 clients, without NA T -T T esting the tunnel The simplest wa y to tell if traffic is passing th rough the tunnel is to perform a tr acer ou te from the Windows 20 00 client to a PC in the r outer’ s LAN.
USA Headq u ar ters | 19800 Nor th Cr eek Parkwa y | S u ite 200 | Bothell | WA 98011 | USA | T: +1 800 424 4284 | F: +1 425 481 3895 E u r opea n Headq u ar ters | Via Motta 24 | 6830 Chiasso | Switzerla n d | T: +41 91 69769.
Un punto importante, dopo l’acquisto del dispositivo (o anche prima di acquisto) è quello di leggere il manuale. Dobbiamo farlo per diversi motivi semplici:
Se non hai ancora comprato il Allied Telesis VPN è un buon momento per familiarizzare con i dati di base del prodotto. Prime consultare le pagine iniziali del manuale d’uso, che si trova al di sopra. Dovresti trovare lì i dati tecnici più importanti del Allied Telesis VPN - in questo modo è possibile verificare se l’apparecchio soddisfa le tue esigenze. Esplorando le pagine segenti del manuali d’uso Allied Telesis VPN imparerai tutte le caratteristiche del prodotto e le informazioni sul suo funzionamento. Le informazioni sul Allied Telesis VPN ti aiuteranno sicuramente a prendere una decisione relativa all’acquisto.
In una situazione in cui hai già il Allied Telesis VPN, ma non hai ancora letto il manuale d’uso, dovresti farlo per le ragioni sopra descritte. Saprai quindi se hai correttamente usato le funzioni disponibili, e se hai commesso errori che possono ridurre la durata di vita del Allied Telesis VPN.
Tuttavia, uno dei ruoli più importanti per l’utente svolti dal manuale d’uso è quello di aiutare a risolvere i problemi con il Allied Telesis VPN. Quasi sempre, ci troverai Troubleshooting, cioè i guasti più frequenti e malfunzionamenti del dispositivo Allied Telesis VPN insieme con le istruzioni su come risolverli. Anche se non si riesci a risolvere il problema, il manuale d’uso ti mostrerà il percorso di ulteriori procedimenti – il contatto con il centro servizio clienti o il servizio più vicino.