
11-6
VPN 3002 Hardware Client Reference, Release 4.0
OL-3813-01
Chapter 11 Policy Management
Configuration | Policy Management | Traffic Management | PAT
Data Initiation
After the tunnel is established between the VPN 3002 and the central-site VPN Concentrator, the VPN
Concentrator can initiate data exchange only in Network Extension mode with all traffic travelling
through the tunnel. If you want the tunnel to remain up indefinitely, configure the VPN 3002 for Network
Extension mode and do not use split tunneling.
Table 11-1 summarizes instances in which the VPN 3002 and the central-site VPN Concentrator can
initiate data exchange.
Table 11-1 Data Initiation: VPN 3002 and Central-Site VPN Concentrator
Configuration | Policy Management | Traffic Management | PAT
When you click PAT in the Configuration | Policy Management | Traffic Management screen, the
Configuration | Policy Management | Traffic Management | PAT screen displays.
Figure 11-3 Configuration | Policy Management | Traffic Management | PAT Screen
PAT mode provides many-to-one translation; that is, it translates many private network addresses to the
single address configured on the public network interface.
Enable
To enable PAT, click Enable.
Mode Tunneling Policy
VPN 3002 Can Send
Data First
Central-Site VPN Concentrator Can Send Data
First (after VPN 3002 initiates the tunnel)
PAT All traffic tunneled Yes No
PAT Split tunneling
enabled
Yes No
Network
Extension
All traffic tunneled Yes Yes
Network
Extension
Split tunneling
enabled
Yes No
Comentarios a estos manuales