Warning: session_start() [function.session-start]: open(/tmp/sess_f81da4d2b619779e941d82cab632a05f, O_RDWR) failed: No space left on device (28) in /home/ciscoart/public_html/include/includes.php on line 17

Warning: session_start() [function.session-start]: Cannot send session cookie - headers already sent by (output started at /home/ciscoart/public_html/include/includes.php:17) in /home/ciscoart/public_html/include/includes.php on line 17

Warning: session_start() [function.session-start]: Cannot send session cache limiter - headers already sent (output started at /home/ciscoart/public_html/include/includes.php:17) in /home/ciscoart/public_html/include/includes.php on line 17

Warning: Cannot modify header information - headers already sent by (output started at /home/ciscoart/public_html/include/includes.php:17) in /home/ciscoart/public_html/include/header.php on line 17
The VPN Concentrators in LAN-to-LAN VPNs
Header
Home | Set as homepage | Add to favorites
  Search the Site     » Advanced Search
Sections
Syndication


Blogroll:

||||| ALL Cisco-Network ARTICLES |||||  
CCIE Journey,
The CCIE Journey,


The VPN Concentrators in LAN-to-LAN VPNs

Dec 31,2009 by alperen

image

LAN-to-LAN (site-to-site) VPNs are a quickly expanding alternative or augmentation to leased line or frame relay WAN infrastructures. VPNs are used to create secure tunnels between two networks via an insecure public network, such as the Internet. The Cisco Concentrator supports three types of tunnels: Layer 2 Tunneling Protocol (L2TP), Point- to-Point Tunneling Protocol (PPTP), and IPSec.

Two types of LAN-to-LAN VPN implementations exist.

  • Intranet VPNs provide secure connections between branch offices to the enterprise network resources.

  • Extranet VPNs provide secure connections for special third parties, such as business partners, vendors, and customers to the specified enterprise resources.

While this chapter and the certification exam focus mainly on the Cisco VPN 3000 Concentrators for LAN-to-LAN implementations, note that the VPN peer device at the other end of this type of link can be any of the following common technologies:

Figure 16-1 shows common intranet and extranet VPNs, as well as the different types of Cisco endpoint devices that might be used.

Click To expand
Figure 16-1: Common LAN-to-LAN VPN implementations

In a LAN-to-LAN implementation, IPSec creates a secure tunnel between the public interfaces of the two VPN Concentrators or endpoint devices. The endpoint devices forward the secure data received over the VPN to the hosts on their private LANs as unencrypted data. No VPN user authentication or configuration exists in a LAN-to-LAN connection. Hosts configured on the private networks can access hosts on the other side of the connection. Any access is subject to any network authentication, group or user permissions, and router access lists.

To configure a LAN-to-LAN connection fully, you must configure identical basic IKE and IPSec parameters on both endpoint devices.


STUDY TIP 

Remember, the IPSec VPN related ports on all network devices between the endpoints must be open. The ports are IKE/ISAKMP UDP port 500, ESP IP protocol number 50, and AH IP protocol number 51.

Chapter Scenario

The scenario used in the following discussion is quite simple, in case someone wants to follow along with appropriate devices. The configuration is based on Figure 16-2, showing a branch location connecting through a VPN Concentrator to another VPN Concentrator at the main office. The scenario assumes the main office has reserved the 128 class C networks 192.168.0.0 to 192.168.127.0 for its internal use. The other private class C addresses have been assigned as needed to the company’s branch locations. The figure shows a branch location assigned the 192.168.144.0 network.

Click To expand
Figure 16-2: VPN 3002 configuration scenario

While the diagram assumes a Concentrator at both ends, the central site configuration process won’t change much, regardless of the device at the branch. You might need to modify the IKE and IPSec choices based on what the peer device can support.


680 times read

Related news

» Cisco VPN 3000 LAN-to-LAN Networks Review
by alperen posted on Dec 31,2009
» Basic Configuration for the VPN 3002
by alperen posted on Nov 22,2009
» The VPN 3002 in the Network
by alperen posted on Nov 19,2009
» Site to Site
by alperen posted on Sep 22,2009
» Cisco VPN 3000 Remote Access Networks
by admin posted on Nov 14,2009
Did you enjoy this article?
(total 0 votes)

comment Comments (0 posted) 

More Top News
CCSP-Cisco Certified Security Professional
Most Popular
Most Commented
Featured Author

Warning: Unknown: open(/tmp/sess_f81da4d2b619779e941d82cab632a05f, O_RDWR) failed: No space left on device (28) in Unknown on line 0

Warning: Unknown: Failed to write session data (files). Please verify that the current setting of session.save_path is correct (/tmp) in Unknown on line 0