Articles Articles Most Popular Articles Most Popular Articles Most Helpful Articles Most Helpful Articles
DrillDown Icon Table of Contents Back
 . . . . . . . . . . . . .
DrillDown Icon What's New
DrillDown Icon Knowledge Base Information
DrillDown Icon Cyberoam UTM
DrillDown Icon Product Literature
DrillDown Icon Best Practices & Policies
DrillDown Icon Protect Your Cyberoam Appliances from Power Fluctuations
DrillDown Icon Version 10.x
DrillDown Icon Cyberoam Maintenance
DrillDown Icon FAQ's
DrillDown Icon How To
DrillDown Icon Anti Spam
DrillDown Icon Anti Virus
DrillDown Icon Authentication
DrillDown Icon Clients
DrillDown Icon Content Filtering
DrillDown Icon Firewall
DrillDown Icon Identity-based Policies
DrillDown Icon IPS
DrillDown Icon Logs & Reports
DrillDown Icon Multiple Gateway - Load Balancing and Failover
DrillDown Icon Quality of Service (QoS)
DrillDown Icon Registration
DrillDown Icon Routing
DrillDown Icon SSL VPN
DrillDown Icon System
DrillDown Icon Users and Groups
DrillDown Icon Virtual LANs
DrillDown Icon VPN
DrillDown Icon VPN Interoperability
DrillDown Icon Route all BO Internet Traffic through HO ISP Gateway
DrillDown Icon Configure a Virtual Host over VPN
DrillDown Icon Configure IPSec VPN Connection with Multiple End Points
DrillDown Icon Bypass IPSec VPN Traffic
DrillDown Icon Allow Clientless SSO (CTAS) Authentication Over VPN
DrillDown Icon Allow Branch Office Users to Authenticate with Head Office Authentication Server
DrillDown Icon Forward GRE Traffic over IPSec VPN Tunnel
DrillDown Icon Create Hub and Spoke IPSec VPN Network with Super Net
DrillDown Icon Manage Cyberoam Through SNMP Over VPN
DrillDown Icon Configure Syslog over VPN in Cyberoam
DrillDown Icon Configure GRE Tunnel on Cyberoam
DrillDown Icon Configure DHCP over VPN in Cyberoam
DrillDown Icon Configure VPN Failover and Failback in Cyberoam
DrillDown Icon Use VPN/MPLS as a Backup(MPLS Scenario)
DrillDown Icon Establish Site-to-Site IPSec Connection using Preshared key
DrillDown Icon Web Application Firewall (WAF)
DrillDown Icon Wireless LAN
DrillDown Icon Configure Wireless WAN
DrillDown Icon TroubleShooting
DrillDown Icon Visio Stencils
DrillDown Icon Glossary
DrillDown Icon Product Technical Support
DrillDown Icon Compatibility
DrillDown Icon Cyberoam Virtual UTM
DrillDown Icon Endpoint Data Protection
DrillDown Icon Cyberoam SSL VPN
DrillDown Icon Cyberoam iView
DrillDown Icon Cyberoam Central Console
DrillDown Icon Cyberoam's On-Cloud Management Service
  Email This ArticlePrintPrint Current Article and All Sub-Articles
 
Bypass IPSec VPN Traffic

Applicable Version: 10.00 onwards
 
Scenario
 
Cyberoam should bypass the IPSec VPN traffic between Site A and Site B, in other words, between Router A and Firewall B. The network schema is as given below.
 
 
 
 

Configuration

Cyberoam can bypass IPSec VPN traffic if it has its UDP ports 500 and 4500 open both from WAN and LAN sides. To open the ports, follow the steps given below. The configuration is to be done from Web Admin Console using Administrator profile. 

Step 1: Create Virtual Host for UDP port 500

Go to Firewall à Virtual Host à Virtual Host and click Add to create a new virtual host according to parameters given below.
 
 
 
 
Parameter Description

 
 
 
On clicking OK, you are asked to create Firewall Rules to allow access to the virtual host created.
 

Step 2: Add Firewall Rule

On clicking OK, the following screen is displayed prompting you to create Firewall Rules.
 
 
 

Enable Add Firewall Rule(s) For Virtual Host and specify parameters shown in the screen as required. Click Add Rule(s) to add the firewall rule. The above firewall rule forwards all traffic from port 500 on WAN side to port 500 on the LAN side.


Step 3: Create Virtual Host for UDP port 4500

Go to Firewall à Virtual Host à Virtual Host and click Add to create a new virtual host according to parameters given below.
 
 
 
 
Parameter Description
Parameter
Value
Description
Name
UDP_Port_4500
Name to identify the Virtual Host.
External IP
#PortC – 10.10.1.1
External IP address is the IP address through which Internet users access internal server/host.
Mapped IP
172.16.16.20
Mapped IP address is the IP address of the internal server/host.
Physical Zone
LAN
LAN, WAN, DMZ, VPN or custom zone of the mapped IP addresses. For example, if mapped IP address represents any internal server then the zone in which server resides physically.
Port Forwarding
Enable Port Forwarding
Enabled
Click to enable service port forwarding.
Protocol
UDP
Select the protocol TCP or UDP that you want the forwarded packets to use.
Port Type
Port
Click to specify whether port mapping should be single or range of ports.
External Port
4500
Specify public port number for which you want to configure port forwarding.
Mapped Port
4500
Specify mapped port number on the destination network to which the public port number is mapped.

 
 
 
On clicking OK, you are asked to create Firewall Rules to allow access to the virtual host created.
 

Step 4: Add Firewall Rule

On clicking OK, the following screen is displayed prompting you to create Firewall Rules.
 
 
 
 
Enable Add Firewall Rule(s) For Virtual Host and specify parameters shown in the screen as required. Click Add Rule(s) to add the firewall rule. The above firewall rule forwards all traffic from port 4500 on WAN side to port 4500 on the LAN side.
 

Note:

Ensure that there exists a similar Firewall Rules which forward all traffic from port 500 and 4500 on LAN side to port 500 and 4500 respectively on the WAN side.
 
 


                                                                                                                                                                                           Document Version: 1.0 – 28/06/2012
Attachments
Article ID: 2370