User's Manual

Table Of Contents
Fortress ES-Series CLI Guide: Network Security, Authentication and Auditing
135
NOTE:
Mesh Points
must be correctly
configured for FastPath
Mesh, as described in
Section 3.2.2, in order for
dynamic endpoint IPsec
SAs to work properly.
4.4.3.1 Dynamic Endpoints for FastPath Mesh Networks
When FastPath Mesh is enabled and L2TP is disabled,
networked Mesh Points can be configured to use dynamic SPD
rules to transparently provide IPsec SAs over the flexible
bridging links comprising the FastPath Mesh WDS (wireless
distribution system).
Most simply, you can configure dynamic-endpoint IPsec SAs
for the FastPath Mesh network by configuring the same
dynamic SPD rule for the bridging interface on each FastPath
Mesh Point (FPMP) through which a Non-Mesh Point (NMP)
may connect:
Policy Name:
meshALL
Priority:
50
Interface:
FPmesh
Local:
0.0.0.0/0.0.0.0
Remote:
0.0.0.0/0.0.0.0
Action:
Apply
Peer Address:
0.0.0.0
A dynamic SPD rule like the one above must be configured on
the FPMPs at both endpoints of the dynamic IPsec tunnel,
which is formed on-demand, when these SPD rules are
triggered. Either endpoint can initiate the IKE transaction to
begin the creation of an IPsec SA over the WDS connection.
Only one such SPD rule—as configured on each endpoint
Mesh Point—is required, and only one pair of IPsec SAs is
created, per IPsec tunnel, over each FastPath Mesh
WDS-enabled bridging BSS.
An SPD entry like the one above is required only for the WDS
bridging interfaces on FPMPs intended to provide network
connectivity for NMP/hosts.
Once WDS IPsec SAs are established, IPsec uses the
FastPath Mesh routing tables to route access network traffic for
Non-Mesh Point (NMP) host devices on the network into the
correct SAs. A connected NMP/host can roam between Mesh
Point access interfaces with no change to the FastPath Mesh
network WDS IPsec SAs.
4.4.3.2 Dynamic Endpoints for VPN Client Connections
with dynamic client IP addresses
Dynamic IPsec endpoints permit VPN clients whose
IP addresses are themselves dynamically established (or
otherwise unknown) to connect to the network.
After a remote VPN client has successfully authenticated
(via pre-shared key exchange or digital certificate), the Mesh
Point dynamically creates and applies an SPD rule for it,
automatically configured with the authenticated client’s
IP address as the
Peer Address for the SPD rule.