
36 MergePoint 5224/5240 Service Processor Manager Installer and Administrator Guide
The administrator must perform the following tasks on the MergePoint 5224/5240 SP manager:
• Make sure that the IPSec service is enabled.
• Configure an IPSec VPN connection profile.
• Give the user the parameters used to configure the IPSec connection profile. One way to do
this is to email the user a copy of the relevant portions of SP manager’s ipsec.conf file.
The authorized user must perform the following tasks:
• Use the same values used by the SP manager administrator to create an IPSec VPN connection
profile on the user’s workstation.
If the administrator emails the relevant portions of the ipsec.conf file from the SP manager, use
it to replace the same section in the workstation’s ipsec.conf file.
• Ensure that routes are in place to allow IPSec communication with the SP manager and also to
allow packets to the target device to be routed through that tunnel.
• Create the IPSec VPN connection.
NOTE: If a virtual network has not been configured, the user may need to create a separate tunnel to each
private subnet they wish to access. If a virtual network has been configured, the user needs only to create a
single tunnel to the virtual network.
• Use either a browser or ssh on the command line to access the SP manager, using the
appliance
-side IP address. Use the appliance-side IP address configured when the private
subnet or virtual network to which the tunnel is connected was being configured.
• Through the SP manager, enable native IP access to the target device.
PPTP VPN connections
For an authorized user to access native IP functionality on a connected SP, the user must create a
VPN connection to the SP manager. An authorized user can create PPTP VPN connections from
Linux, Windows or Macintosh operating systems.
The tasks listed below must be performed by the SP manager administrator before any user can
make a PPTP VPN connection:
• Create a VPN connection profile on the SP manager specifying a pool of addresses for the SP
manager and for the remote user’s computer at the other end.
When the user creates the PPTP VPN connection, PPTP creates a new virtual interface on the
user’s host and assigns an IP address from the SP manager’s IP address pool to the interface.
The user must use this address when connecting to the SP manager to enable native IP access
to a target device.
• Authorize the user for PPTP access and provide the user with the PPTP password, which may
be different from the user’s password for accessing the SP manager.
• Authorize the user for native IP access to one or more target devices.
Komentáře k této Příručce