We try to configure the hand L2TP / IPsec, this simple point, the network topology See all 03 intermediate tutorial.
A, HQ router configuration:
First, we must first configure the IP, the IP can be used to connect up communications after the branch.
IP configuration, there are two, one is DHCP, one is assigned to IP.
In the enterprise branch interconnection, ROS and ROS docking, the tendency to assign IP, so that management is more convenient, and assigning IP, then the account is configured inside, so we went with the account.
Three-tier exchange wrote a default route
1. Configure account and IP
Click PPP> Secrets Click on the + sign to create a new account
Pop-up window Description:
At the headquarters router can automatically route to the end of the injection.
Speed:
The same configuration of the three branches account
2. Enable L2TP and IPSec settings Password:
Well, that's the headquarters of ROS router set up.
Second, the branch configuration ROS
PPPOE and segments like configuration is not to say, you can see basic tutorial.
Or click PPP> Click the plus sign, select L2TP Client
Sets the name of the routine inside
Switch to Dial Out, set the following parameters:
Click OK, to start the connection.
Logs can be seen inside the following parameters:
Why will first use the 500 port, and then use the 4500 port, this is because we PPPOE network, in the middle do NAT, then use port 4500. Port 500 is a public network to the public network.
Similarly, we look to configure L2TP / IPSec between OfficeB and OfficeC, ignored here. ( In fact, because L2TP / IPSEC only one client. The client common to a plurality of connection will be off at the top in a public NAT IP connection to a public IP network. Topology as now need three PPPOE server can so ... )
Third, configure routing
1. Headquarters:
Just create L2TP account when routing the headquarters we have it automatically configured.
Click IP> Routes can see the route has been automatically added.
At this point we can ping the headquarters of the branch network.
2. branch routing table configuration
Branch was not generated automatically routing information, so you want to manually configure the routing table about what to inform the headquarters of the network router yes.
Click IP> Routes
Further a configuration same network segment 192.168.13.0
Then arranged in the same route branch B, C of the branch.
3. Test connectivity to the branch headquarters, has been up to.
:( computer test in accordance with the topology, test PC1, PC2, PC3 network connectivity)
Finish