User manual

www.cooperbussmann.com/wirelessresources
Cooper Bussmann 615M-1 Cellular Data Modem and IP Router Series Manual
61Rev Version 1.0
ChapTEr 5 - IpSEC aND vpN paSS-ThrOUGh DEplOyMENT GUIDE
This chapter provides information on building a secure IP network using IPSec and the ELPRO 615M-1 Cellular
Modem. Two configuration scenarios are provided. The first scenario demonstrates the 615M-1 when used as an
IPSec client. The second scenario shows the 615M-1 passing an IPSec connection from WAN to LAN (VPN pass-
through). Detailed configuration examples are provided for each scenario.
7.1 Benefits of IPsec
Internet Protocol Security Standard (IPSec) is an industry driven standard that ensures confidentiality, integrity, and
authenticity of an IP network. IPSec is a key component of this standard-based, flexible solution for deploying a
network-wide policy.
There are two significant benefits to IPSec compliance for our customers—enhanced security features and
interoperability.
• Enhanced security features give our customers the comfort of knowing that IP based communications are
using the most secure and comprehensive standard available today for encryption and authentication.
The 615M-1 IPSec encryption support: AES-128, AES-256 and 3DES
The 615M-1 IPSec authentication support: MD5 and SHA1
All tunnels are created using the ESP (Encapsulating Security Payload) protocol.
• Protocol interoperability means that an IPSec-compliant device, such as the 615M-1, will be able to exchange
keys and encrypted communications with another IPSec-compliant product such as a Cisco™ router. IPSEC
compliance ensures that these two different products can negotiate and maintain a secure communication with
each other.
7.2 615M-1 Configured IPsec Client
In the following configuration examples, the 615M-1 is used as an IPSEC Client to connect to a Cisco Router acting
as a VPN server.
Where:
rEMOTE SUBNET: 10.100.0.0/21
FIrEWall ExTErNal Ip (rEMOTE Ip): A.B.C.D
615M-1 ppp Ip (lOCal Ip): W.X.Y.Z
lOCal SUBNET: 10.100.10.0/24
Figure 37 615M-1 Configured IPSEC Client