
11-2
VPN 3002 Hardware Client Reference, Release 4.0
OL-3813-01
Chapter 11 Policy Management
Configuration | Policy Management | Traffic Management
Certificate Validation
To enable and set criteria that must match for the VPN 3002 to verify a certificate from the Concentrator
to which it connects, click Certificate Validation.
Configuration | Policy Management | Traffic Management
When you click Traffic Management on the Configuration | Policy Management screen, the Manager
displays the Configuration | Policy Management | Traffic Management screen.
Figure 11-2 Configuration | Policy Management | Traffic Management Screen
PAT
To configure PAT (Port Address Translation) click PAT.
About PAT (Client Mode)
Client mode, also called Port Address Translation (PAT) mode, isolates all devices on the VPN 3002
private network from those on the corporate network. In PAT mode:
• IPSec encapsulates all traffic going from the private network of the VPN 3002 to the network(s)
behind the Internet Key Exchange (IKE) peer, that is, the central-site VPN Concentrator.
• PAT mode uses NAT (Network Address Translation). NAT translates the network addresses of the
devices connected to the VPN 3002 private interface to the IP address of the VPN 3002 public
interface. The VPN Concentrator assigns this address. NAT also keeps track of these mappings so
that it can forward replies to the correct device.
All traffic from the private network appears on the network behind the IKE peer with a single source IP
address. This IP address is the one the central-site VPN Concentrator assigns to the VPN 3002. The IP
addresses of the computers on the VPN 3002 private network are hidden. You cannot ping or access a
device on the VPN 3002 private network from outside of that private network, or directly from a device
on the private network at the central site.
In client mode, the tunnel establishes when data passes to the VPN Concentrator, or when you click
Connect Now in the Monitoring | System Status screen.
Comentarios a estos manuales