Sample configuration Implementing Single Connections-to-LAN Tunnels

101 Figure 6-2. A typical PC-to-LAN tunnel configuration

6.4.2.2 Tunnel server configuration

Routing table The routing table is set up to route all tunnel sessions to the local LANs physical network: 1.195.6.. All dynamic IP addresses are routed to this network for tunnel traffic. • SubNet : 1.195.6. • NetMask : 255.255.255.0 • Description : Local Hosts Dynamic IP table The dynamic IP range starts at 1.196.5.1 and comprises a Class C network 255 addresses. The tunnel server on the corporate LAN is set up to connect multiple single PC tunnel connections, and routes all tunnel traffic to its physical network from the routing parameters above. • Range name : Sales Tunnel. • Range description : Remote Tunnel Clients. • First IP : 1.196.5.1. • Total tunnels : The total number of tunnels for this tunnel group is set to 128. As each tunnel session is assigned two IP addresses, this makes the total IP address range equal to 256 IP addresses. • NetMask : 255.255.255.0 for the 256 IP virtual network. 102 Authentication table The group name for this tunnel is Sales. The password is Bubba. These two parameters have been extracted into an ETA file called sales.eta and distributed via floppy disk to the various tunnel clients. The key file has been created by the tunnel server on the corporate LAN and is specific to this tunnel group. The key file has also been extracted and distributed via floppy disk. By default, this key file is named sales.key.

6.4.2.3 Firewall configuration

The local firewall is configured to relay all external tunnel requests those reaching 1.195.6.1 on port 3265 to the tunnel server at its physical IP address: 1.195.6.2, port 3265.

6.4.2.4 Local host configuration

The host machines on the corporate LAN have a default route to 1.195.6.2, the tunnel servers physical IP address. Any traffic destined for the tunnel takes the tunnel servers virtual IP end of the tunnel; all other traffic bound for outside the local network passes to the firewall and out to the Internet.

6.4.2.5 Remote PC configuration

The remote PCs Telecommuter Client Tunnel client is configured to route all tunnel traffic to the dynamic IP address assigned by the remote tunnel server. Within the tunnel client software, the tunnel group is defined like this: Username The name of this tunnel group is Sales. There is also a password Bubba, which must be manually entered when a tunnel session is opened. Server key ID The local key file is sales.key. It is stored with the ETA file obtained from the remote tunnel server in this case via floppy disk. Tunnel server The tunnel servers physical IP address is 1.195.6.2, with a tunnel traffic port of 3265. First Firewall Unused in this case. Second Firewall The IP address to the remote LANs firewall is 1.195.6.1, with a tunnel traffic port of 3265.