Professional Documents
Culture Documents
This article describes how to configure Cyberoam Firewall/VPN in a hub and spoke VPN
system, as might be used in a headquarters with many branch offices.
In a hub and spoke network, all VPN tunnels terminate at the hub. Hub functions as a
concentrator on the network, managing all VPN connections between the spokes. Site-to-
Site connection between the spokes does not exist but the VPN traffic passes from one
tunnel to the other via the hub.
In the example throughout the article, below given IP addresses are assigned to
Cyberoam deployed at headquarter and 2 branches. Follow the steps for setting up the
example hub-and-spoke VPN configuration to create a VPN among Houston branch
(Cyberoam_br1), Dallas branch (Cyberoam_br2) and the New York Head office
(Cyberoam_ho) network.
IP addressing scheme
Configuration
Houston Branch (Cyberoam_br1)
Parameters
Preshared key Houston_key
Local Network Local Server (WAN IP address) 202.10.10.10
details Local LAN address 5.5.5.0/16
Local ID john@elitecore.com
Remote Network Remote VPN server (Hub IP address) 202.11.11.11
details Remote LAN Network
10.10.10.0/24 (Dallas Network)
192.168.1.0/24 (New York Network)
Remote ID dean@elitecore.com
Remote ID dean@elitecore.com
Configuration
Dallas Branch (Cyberoam_br2)
Parameters
Preshared key Dallas_key
Local Network Local Server (WAN IP address) 202.12.12.12
details Local LAN address 10.10.10.0/24
Local ID mathews@elitecore.com
Remote Network Remote VPN server (Hub IP address) 202.11.11.11
details Remote LAN Network
5.5.5.0/16 (Houston Network)
192.168.1.0/24 (New York Network)
Remote ID anthony@elitecore.com
Mode: Tunnel
Connection Type: Net to Net
Note
At a time only one connection can be active if both the types of connection - Digital
Certificate and Preshared Key - are created with the same source and destination. In such
situation, at the time of activation, you will receive error unable to activate connection
hence you need to deactivate all other connections.
Go to Firewall Create Rule and create rule with the following values:
Action: Accept
How To Create Hub and Spoke IPSec VPN network
Configuration
New York to Houston
Parameters
Preshared key Houston_key
Local Network Local Server (WAN IP address) 202.11.11.11
details Local LAN address
192.168.1.0/24
10.10.10.0/24
Local ID dean@elitecore.com
Remote Network Remote VPN server (Houston) 202.10.10.10
details Remote LAN Network
5.5.5.0/16
Remote ID john@elitecore.com
Go to VPN IPSec Connection Create Connection and create connection with the
following values:
How To Create Hub and Spoke IPSec VPN network
Configuration
New York to Dallas
Parameters
Preshared key Dallas_key
Local Network details Local Server (WAN IP address) 202.11.11.11
Local LAN address
192.168.1.0/24
5.5.5.0/16
Local ID anthony@elitecore.com
Remote Network Remote VPN server (Houston) 202.12.12.12
details Remote LAN Network
10.10.10.0/24
Remote ID mathews@elitecore.com
Go to VPN IPSec Connection Create Connection and create connection with the
following values:
Note
At a time only one connection can be active if both the types of connection - Digital
Certificate and Preshared Key - are created with the same source and destination. In such
situation, at the time of activation, you will receive error unable to activate connection
hence you need to deactivate all other connections.
You can establish connection, once the all three servers are configured. You can establish
connection from either of the servers.
Go to VPN IPSec Connection Manage Connection and click against the connection
under the Connection status indicates that the connection is successfully established.
If you are not able to establish the connection, check VPN log from Telnet Console. Refer
to VPN Troubleshooting Guide for log explanation and error solution.
Testing Connection
To check the connectivity between New York office to Houston branch and vice versa:
ping Cyberoam_br1 LAN interface from Cyberoam_ho LAN interface
ping Cyberoam_ho LAN interface from Cyberoam_br1 LAN interface
To check the connectivity between New York office to Dallas branch and vice versa:
ping Cyberoam_br2 LAN interface from Cyberoam_ho LAN interface
How To Create Hub and Spoke IPSec VPN network
To check the connectivity between Houston branch to Dallas branch and vice versa:
ping Cyberoam_br2 LAN interface from Cyberoam_br1 LAN interface
ping Cyberoam_br1 LAN interface from Cyberoam_br2 LAN interface
Reference Documents
VPN Troubleshooting Guide