![]() ![]() ![]() ![]()
|
Complete PDF manual
PDF of This Chapter
Step 2: Configuring the NETGEAR ProSafe VPN Client on the Remote PC at the Telecommuter's Home Office
This procedure describes how to configure the DG834 ADSL Modem Router. We will assume the PC running the client has a dynamically assigned IP address.
The PC must have a VPN client program installed that supports IPSec (in this case study, the NETGEAR VPN ProSafe Client is used). Go to the NETGEAR website (http://www.netgear.com) and select VPN01L_VPN05L in the Product Quick Find drop-down menu for information on how to purchase the NETGEAR ProSafe VPN Client.
![]()
Note: Before installing the DG834 ADSL Modem Router software, be sure to turn off any virus protection or firewall software you may be running on your PC.
- Install the NETGEA ProSafe VPN Client on the remote PC and reboot.
- You may need to insert your Windows CD to complete the installation.
- If you do not have a modem or dial-up adapter installed in your PC, you may see the warning message stating "The NETGEAR ProSafe VPN Component requires at least one dial-up adapter be installed." You can disregard this message.
- Install the IPSec Component. You may have the option to install either the VPN Adapter or the IPSec Component or both. The VPN Adapter is not necessary.
- The system should show the ProSafe icon (
) in the system tray after rebooting.
- Double-click the system tray icon to open the Security Policy Editor.
- Add a new connection.
- Run the NETGEAR ProSafe Security Policy Editor program and create a VPN Connection.
- From the Edit menu of the Security Policy Editor, click Add, then Connection. A New Connection listing appears in the list of policies. Rename the New Connection so that it matches the Connection Name you entered in the VPN Settings of the DG834 on Gateway A.
![]()
Note: In this example, the Connection Name used on the client side of the VPN tunnel is toDG834G and it does not have to match the VPN_client Connection Name used on the gateway side of the VPN tunnel (see Figure B-16) because Connection Names are arbitrary to how the VPN tunnel functions.- Select Secure in the Connection Security check box.
- Select IP Subnet in the ID Type menu.
- In this example, type 192.168.0.1 in the Subnet field as the network address of the DG834.
- Enter 255.255.255.0 in the Mask field as the LAN Subnet Mask of the DG834.
- Select All in the Protocol menu to allow all traffic through the VPN tunnel.
- Select the Connect using Secure Gateway Tunnel check box.
- Select Domain Name in the ID Type menu below the check box and enter fromDG834G.com (in this example).
- Select Gateway Hostname and enter ntgr.dyndns.org (in this example).
- The resulting Connection Settings are shown in Figure B-16.
- Configure the Security Policy in the DG834 ADSL Modem Router software.
- Configure the VPN Client Identity.
In this step, you will provide information about the remote VPN client PC. You will need to provide the Pre-Shared Key that you configured in the DG834 and either a fixed IP address or a "fixed virtual" IP address of the VPN client PC.
- In the Network Security Policy list on the left side of the Security Policy Editor window, click My Identity.
- Choose None in the Select Certificate menu.
- Select Domain Name in the ID Type menu and enter toDG834G.com (in this example) in the box below it. Choose Disabled in the Virtual Adapter menu.
- In the Internet Interface box, select Intel PRO/100VE Network Connection (in this example, your Ethernet adapter may be different) in the Name menu and enter 192.168.2.3 (in this example) in the IP Addr box.
- Configure the VPN Client Authentication Proposal.
In this step, you will provide the type of encryption (DES or 3DES) to be used for this connection. This selection must match your selection in the VPN router configuration.
- In the Network Security Policy list on the left side of the Security Policy Editor window, expand the Security Policy heading by double clicking its name or clicking on the "+" symbol.
- Expand the Authentication subheading by double clicking its name or clicking on the "+" symbol. Then select Proposal 1 below Authentication.
- In the Authentication Method menu, select Pre-Shared key.
- In the Encrypt Alg menu, select the type of encryption. In this example, use Triple DES.
- In the Hash Alg menu, select SHA-1.
- In the SA Life menu, select Unspecified.
- In the Key Group menu, select Diffie-Hellman Group 2.
- Configure the VPN Client Key Exchange Proposal.
In this step, you will provide the type of encryption (DES or 3DES) to be used for this connection. This selection must match your selection in the VPN router configuration.
- Expand the Key Exchange subheading by double clicking its name or clicking on the "+" symbol. Then select Proposal 1 below Key Exchange.
- In the SA Life menu, select Unspecified.
- In the Compression menu, select None.
- Check the Encapsulation Protocol (ESP) checkbox.
- In the Encrypt Alg menu, select the type of encryption. In this example, use Triple DES.
- In the Hash Alg menu, select SHA-1.
- In the Encapsulation menu, select Tunnel.
- Leave the Authentication Protocol (AH) checkbox unchecked.
- Save the VPN Client settings.
From the File menu at the top of the Security Policy Editor window, select Save.
After you have configured and saved the VPN client information, your PC will automatically open the VPN connection when you attempt to access any IP addresses in the range of the remote VPN router's LAN.
- Check the VPN Connection.
To check the VPN Connection, you can initiate a request from the remote PC to the VPN router's network by using the Connect option in the DG834 ADSL Modem Router menu bar (see Figure B-22). Since the remote PC has a dynamically assigned WAN IP address, it must initiate the request.
- Right-click the system tray icon to open the popup menu.
- Select Connect to open the My Connections list.
- Choose toDG834G.
The DG834 ADSL Modem Router will report the results of the attempt to connect. Once the connection is established, you can access resources of the network connected to the VPN router.
To perform a ping test using our example, start from the remote PC:
- Establish an Internet connection from the PC.
- On the Windows taskbar, click the Start button, and then click Run.
This will cause a continuous ping to be sent to the VPN router. After between several seconds and two minutes, the ping response should change from timed out to reply.
Once the connection is established, you can open the browser of the PC and enter the LAN IP address of the VPN router. After a short wait, you should see the login screen of the VPN router (unless another PC already has the VPN router management interface open).
![]()
Note: You can use the VPN router diagnostic utilities to test the VPN connection from the VPN router to the client PC. Run ping tests from the Diagnostics link of the VPN router main menu.
|
NETGEAR, Inc. http://www.netgear.com |
![]() ![]() ![]() ![]()
202-10133-01,
November 2005 |