D-Link DIR-130 User Manual

D-Link And TheGreenBow Solution
Brr
o
o
a
a
d
d
b
b
a
a
n
n
p
p
d
d
pllii
p
V
V
c
c
P
N
P
attii
a
DII
o
n
o
n
R--
o
utt
o
1
3
1
u
ott
o
Version 1.00
(2009-4-24)
0
3
0
err
e
e
e
D-Link International
Confidential and proprietary
1
Revision History
Date Rev. Description Editor
Interoperability Compliance Testing Negotiate mode for
2009-4-24 1.0
Phase1 and Phase2 using TheGreenBow VPN Client and D­Link product’s DIR-130.
John Yoong
1. Introduction
The objective of this document is to provide a guide describing how to configure the devices to achieve the same environment as show at the network topology.
Users of this document are expected to already possess basic knowledge of D-Link devices and TheGreenBow VPN program, and are familiar with how to perform basic configurations. Only important configurations, such as those pertaining to interfacing and integrating, will be described in this document.
For purpose of reference, configuration files for each device are available for download.
2. Audience
This document is intended for project engineers or end users that need to implement Broadband VPN Router DIR series and TheGreenBow software at the sites.
3. Objective
This topology consist the scenarios that integrates using TheGreenBow VPN program and D-Link Broadband VPN Router DIR-130 and demonstrate integrations and network solutions to OBUs, and in addition, to Partners and Customers from D-Link International.
4. List of Equipment and Software
The table below shows the devices information.
Device No. Device Name Device Model Firmware
1 TheGreenBow VPN Client Software ­4 Broadband VPN Router DIR-130
4.6x
1.20
D-Link International
Confidential and proprietary
2
Network Diagram
5.
Note: DIR-130 Router is set to allow IPSec pass through.
It is important to note that this application note is also applicable to the following VPN routers:
DIR-130
DIR-330
DIR-730
6. Configurations
In this document, we will only describe the main configurations for this Scenario. The configurations setting for all the D-Link products will not be described here and for more detail about the product you can download their user guide.
6.1 TheGreenBow VPN client and D-Link Broadband VPN router solutions (DIR-130)
In this scenario the user can connect back to the Branch office database by using TheGreenBow VPN client tunneling to the Broadband VPN router DIR-130.
All configurations are based on Broadband VPN router DIR-130 (F/W: 1.20 ) and TheGreenBow VPN Client Software (F/W: 4.60.0.0)
The steps in this configuration are:
Setup DIR-130 for VPN tunneling
1. Setup VPN Setting
Setup TheGreenBow VPN client
D-Link International
Confidential and proprietary
3
1. Setup Phase 1
2. Setup Phase 2
6.1.1) Setup DIR-130 for VPN tunneling
6.1.1.1)
1) Click on the “VPN Settings” and add the VPN profile “IPSec”.
Setup VPN Setting
2) First “Enable” the VPN IPSec and follow by filling all the information as
show below according to your network environment.
D-Link International
Confidential and proprietary
4
3) Phase 1 and Phase 2 algorithms must be set the same as The GreenBow VPN Client software. Save the setting for the DIR-130 Broadband VPN Router.
D-Link International
Confidential and proprietary
5
6.1.2) Setup TheGreenBow VPN Client software
D-Link International
Confidential and proprietary
6
6.1.2.1) Setup Phase 1
1) Right click on the “Root” to add a new “Phase1”, next fill in the IP
address for this VPN client and Remote gateway IP follow by Preshared Key and IKE setting.
Note: the Preshared Key and IKE must be the same setting set in the DIR-130.
6.1.2.2) Setup Phase 2
D-Link International
Confidential and proprietary
7
1) Right click on the “Phase1” to add a new “Phase2”, next fill in the
VPN Client address for this VPN client and Remote gateway IP follow by ESP setting.
Note: the ESP Encryption and Authentication setting must be the same in the Broadband VPN Router DIR-130 phase 1 and phase 2 setting.
7. Interoperability Compliance Testing
D-Link International
Confidential and proprietary
8
7.1) General Test Approach
a. Open the VPN tunnel using different Negotiate Mode in Phase 1 and
Phase 2:
Series Negotiate Mode Phase 1 Phase 2 AES-SHA AES-SHA AES-MD5 AES-SHA 3DES-MD5 AES-SHA 3DES-SHA AES-SHA DES-MD5 AES-SHA DES-SHA AES-SHA AES-SHA AES-MD5 AES-MD5 AES-MD5 3DES-MD5 AES-MD5 3DES-SHA AES-MD5 DES-MD5 AES-MD5 DES-SHA AES-MD5 AES-SHA 3DES-SHA AES-MD5 3DES-SHA 3DES-MD5 3DES-SHA 3DES-SHA 3DES-SHA DES-MD5 3DES-SHA DES-SHA 3DES-SHA AES-SHA 3DES-MD5 AES-MD5 3DES-MD5 3DES-MD5 3DES-MD5 3DES-SHA 3DES-MD5 DES-MD5 3DES-MD5 DES-SHA 3DES-MD5 AES-SHA DES-SHA AES-MD5 DES-SHA 3DES-MD5 DES-SHA 3DES-SHA DES-SHA DES-MD5 DES-SHA DES-SHA DES-SHA
D-Link International
9
Confidential and proprietary
Series Negotiate Mode Phase 1 Phase 2 AES-SHA DES-MD5 AES-MD5 DES-MD5 3DES-MD5 DES-MD5 3DES-SHA DES-MD5 DES-MD5 DES-MD5 DES-SHA DES-MD5
7.2) Test Result a. The VPN tunnel will be open at any negotiate mode set in Phase 1
and Phase 2.
D-Link International
Confidential and proprietary
10
TheGreenBow VPN Software
b. The broadband VPN router DIR series will show the tunnel is up at
their VPN status.
DIR-130 VPN Status
c. Client is able to Ping to the remote network.
D-Link International
Confidential and proprietary
11
8. Conclusion
The Application Notes demonstrate how D-Link VPN products and TheGreenBow software combined perfectly address the requirements of the small and medium businesses worldwide. The joint VPN solution offer advantages around multiple access control and authorization mechanisms for users and tunneling capabilities to access the entire corporate network; it can also provide different access rights to different users.
D-Link International
Confidential and proprietary
12
D-Link Inc. All Rights Reserved
D-Link is the worldwide leader and an award-winning designer, develope r, and ma nufacturer of Wi-Fi and Ethernet networking, broadband, multimedia, voice and data communications and digital electronics solutions.
D-Link International
Confidential and proprietary
13
Loading...