SlideShare a Scribd company logo
1
Connecting to the Internet
Henry Lo
Application Engineer
Seminar
2
• Multi LAN Subnets / VLAN
- Port-Based
- Tag-Based
- Inter-LAN Routing
- Hybrid Example — Setup multi-subnets with APs
• LAN-to-LAN VPN
- PPTP and IPSec
- VPN Trunk
• Remote Dial-in VPN
- Smart VPN Client and SSL VPN
• Load-Balance/Route Policy
Outline — Session 1
3
Outline — Session 2
• Content Security Management (CSM)
- Web Content Filter with DNS Filter
- APP Enforcement
• User Management
- Customized Login Page Logo
- Create Accounts for Accommodations
• AP Management
- Setup, Configure, and Maintenance
- Management Methods
• WiFi Airtime Fairness
• Bandwidth Management
4
Outline
• Multi LAN Subnets / VLAN
- Port-Based
- Tag-Based
- Inter-LAN Routing
- Hybrid Example — Setup multi-subnets with APs
• LAN-to-LAN VPN
- PPTP and IPSec
- VPN Trunk
• Remote Dial-in VPN
- Smart VPN Client and SSL VPN
• Load-Balance/Route Policy
5
Multi LAN Subnets / VLAN
• The Initial Status
6
Multi LAN Subnets/VLAN
• Port-Based
7
Multi LAN Subnets/VLAN
• Tag-Based
8
Multi LAN Subnets/VLAN
• A Hybrid Example
- P1 in LAN1 for
Administrator
Management
- P2~P4 in LAN2 for 3
Departments, Isolated
from Each Other
- P5 in LAN1 for Internal
Server (e.g., FTP Server)
- P6 in LAN3 for Guests
9
• Enable 

LAN2 and LAN3
• Enable 

Inter-LAN Routing
Multi LAN Subnets/VLAN
10
• A Hybrid Example
- P1 Administrator
- P2, P3 Staff
- P4 for AP LANA
- P5 for AP LANB
Multi LAN Subnets/VLAN
11
Multi LAN Subnets/VLAN
12
Outline
• Multi LAN Subnets / VLAN
- Port-Based
- Tag-Based
- Inter-LAN Routing
- Hybrid Example — Setup multi-subnets with APs
• LAN-to-LAN VPN
- PPTP and IPSec
- VPN Trunk
• Remote Dial-in VPN
- Smart VPN Client and SSL VPN
• Load-Balance/Route Policy
13
Supported VPN Protocol
• PPTP (TCP 1723)
• L2TP (UDP 1701)
• IPsec (UDP 500)
• L2TP over IPsec
• SSL VPN (TCP 443)
• mOTP
14
Supported VPN Protocols
None/Nice to Have/Must
LAN to LAN
PPTP
L2TP
/IPSec
IPSec
SSL
port configurable V2960/V3900 only
15
LAN-to-LAN VPN
• VPN for more subnets
VPN
172.16.10.1/24 192.168.1.1/24
Headquarters
Dial-in
Branch 1
Dial-out
172.16.15.1/24 192.168.5.1/24
VPN
16
LAN-to-LAN VPN
• Hub and Spokes
VPN172.16.10.1/24
192.168.1.1/24
172.16.20.1/24
Branch 2
VPN 172.16.30.1/24
VPN
172.16.40.1/24
Branch 3
Branch 4
Headquarters
Branch 1
17
LAN-to-LAN VPN
• VPN Trunk — Backup
VPN 1
172.16.10.1/24 192.168.1.1/24
Dial-in
Branch 1
Dial-out
VPN 2
WAN 1
WAN 2
Headquarters
18
LAN-to-LAN VPN
• VPN Trunk — Load Balance
VPN 1
172.16.10.1/24 192.168.1.1/24
Dial-in
Branch 1
Dial-out
VPN 2
WAN 1
WAN 2
Headquarters
19
None/Nice to Have/Must
Host to LAN
PPTP
L2TP
/IPSec
IPSec
SSL
port configurable
PC Android Mac iOS
Must
DrayTek
Smart VPN
Client
DrayTek
Smart VPN
Client
Must Must
20
Remote Dial-In VPN
• Smart VPN Client for Android — SSL VPN
21
Outline
• Multi LAN Subnets / VLAN
- Port-Based
- Tag-Based
- Inter-LAN Routing
- Hybrid Example — Setup multi-subnets with APs
• LAN-to-LAN VPN
- PPTP and IPSec
- VPN Trunk
• Remote Dial-in VPN
- Smart VPN Client and SSL VPN
• Load-Balance/Route Policy
22
General View
23
Configuration Page
24
Configuration Page
• Set Criteria
- Protocol
- Source / Dest IP
- Port
25
Configuration Page
• Choose Route
- Interface
- Gateway
• Give Priority
- Higher than Routing Table?
- Higher than other Policies?
26
Configuration Page
• NAT or Routing?
- Regardless of the original LAN type
• Failover to Interface / Policy
• Gradual / Immediate Failback
27
Idea of Priority
• Compare between Routing Table and Route Policies
100
Index Interface
1
2
Src IP Dest IP
WAN2 LAN2 Any
WAN1 LAN2 8.8.8.8
Priority
100
INTERNET
WAN1 WAN2
LAN1
Servers
LAN2
PC
150
200
INTERNET
WAN1 WAN2
LAN1
Servers
LAN2
PC 28
Idea of Priority
• Compare between Routing Table and Route Policies
Index Interface
1
2
Src IP Dest IP
3
WAN2 LAN2 Any
WAN1 LAN2 8.8.8.8
Priority
200
150
200
INTERNET
WAN1 WAN2
LAN1
Servers
LAN2
PC 29
Idea of Priority
• Compare between Routing Table and Route Policies
Index Interface
1
2
Src IP Dest IP
3
WAN1 LAN2 8.8.8.8
WAN2 LAN2 Any
Priority
200
250
250
• Priority First, Sequence Second
30
Idea of Priority
• Compare between Routing Table and Route Policies
• Priority First, Sequence Second
- With Same Priority, Sequence Matters
31
Idea of Priority
• Compare between Routing Table and Route Policies
32
Route Policy Diagnose
8.8.8.8
33
• Send SIP Traffic to
the Less-Jitter WAN
Load Balance
34
Route Policy with VPN
• Local Users to Remote Server
- Only Specified LAN IP are eligible to
send traffic via the VPN tunnel
Manager IPTV
INTERNET
VPNTunnel
VPN
TunnelVPN Server
Netflix Server
netflix-380.vo.llnwd.net
Employees
35
Q&A

More Related Content

What's hot

EMEA Airheads - Aruba Remote Access Point (RAP) Troubleshooting
EMEA Airheads - Aruba Remote Access Point (RAP) TroubleshootingEMEA Airheads - Aruba Remote Access Point (RAP) Troubleshooting
EMEA Airheads - Aruba Remote Access Point (RAP) Troubleshooting
Aruba, a Hewlett Packard Enterprise company
 
Denovo SIP VoIP Termination SBC Session Boarder Controler @ denofolab.com
Denovo SIP VoIP Termination SBC Session Boarder Controler @ denofolab.comDenovo SIP VoIP Termination SBC Session Boarder Controler @ denofolab.com
Denovo SIP VoIP Termination SBC Session Boarder Controler @ denofolab.com
Anne Kwong
 
A week with analysing RPKI status
A week with analysing RPKI statusA week with analysing RPKI status
A week with analysing RPKI status
APNIC
 
4 ip services dhcp-part b
4 ip services dhcp-part b4 ip services dhcp-part b
4 ip services dhcp-part b
SagarR24
 
EMEA Airheads - AP Discovery Logic and AP Deployment
EMEA Airheads - AP Discovery Logic and AP DeploymentEMEA Airheads - AP Discovery Logic and AP Deployment
EMEA Airheads - AP Discovery Logic and AP Deployment
Aruba, a Hewlett Packard Enterprise company
 
EMEA Airheads- Manage Devices at Branch Office (BOC)
EMEA Airheads- Manage Devices at Branch Office (BOC)EMEA Airheads- Manage Devices at Branch Office (BOC)
EMEA Airheads- Manage Devices at Branch Office (BOC)
Aruba, a Hewlett Packard Enterprise company
 
Iot protocols tr 069
Iot protocols  tr 069Iot protocols  tr 069
Iot protocols tr 069
adorable73
 
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
EMEA Airheads- Virtual Switching Framework- Aruba OS SwitchEMEA Airheads- Virtual Switching Framework- Aruba OS Switch
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
Aruba, a Hewlett Packard Enterprise company
 
EMEA Airheads- ArubaOS - High availability with AP Fast Failover
EMEA Airheads- ArubaOS - High availability with AP Fast FailoverEMEA Airheads- ArubaOS - High availability with AP Fast Failover
EMEA Airheads- ArubaOS - High availability with AP Fast Failover
Aruba, a Hewlett Packard Enterprise company
 
Free OpManager training Part 3 - Monitoring Network Performance and Network Maps
Free OpManager training Part 3 - Monitoring Network Performance and Network MapsFree OpManager training Part 3 - Monitoring Network Performance and Network Maps
Free OpManager training Part 3 - Monitoring Network Performance and Network Maps
ManageEngine, Zoho Corporation
 
4 ip services dhcp
4 ip services dhcp4 ip services dhcp
4 ip services dhcp
SagarR24
 
Route Hijaking and the role of RPKI
Route Hijaking and the role of RPKIRoute Hijaking and the role of RPKI
Route Hijaking and the role of RPKI
APNIC
 
Get vpn multicast for CCIE Security
Get vpn multicast for CCIE SecurityGet vpn multicast for CCIE Security
Get vpn multicast for CCIE Security
Dhruv Sharma
 
Webinar: How to captures and analyzes NetFlow, J-Flow and sFlow data
Webinar: How to captures and analyzes NetFlow, J-Flow and sFlow dataWebinar: How to captures and analyzes NetFlow, J-Flow and sFlow data
Webinar: How to captures and analyzes NetFlow, J-Flow and sFlow data
ManageEngine, Zoho Corporation
 
Ccna routing and switching
Ccna routing and switchingCcna routing and switching
Ccna routing and switching
CRIS FERNANDEZ
 
Free OpManager training Part1- Discovery and classification season#3
Free OpManager training Part1- Discovery and classification season#3Free OpManager training Part1- Discovery and classification season#3
Free OpManager training Part1- Discovery and classification season#3
ManageEngine, Zoho Corporation
 
EMEA Airheads- ArubaOS - Rogue AP troubleshooting
EMEA Airheads- ArubaOS - Rogue AP troubleshootingEMEA Airheads- ArubaOS - Rogue AP troubleshooting
EMEA Airheads- ArubaOS - Rogue AP troubleshooting
Aruba, a Hewlett Packard Enterprise company
 

What's hot (20)

EMEA Airheads - Aruba Remote Access Point (RAP) Troubleshooting
EMEA Airheads - Aruba Remote Access Point (RAP) TroubleshootingEMEA Airheads - Aruba Remote Access Point (RAP) Troubleshooting
EMEA Airheads - Aruba Remote Access Point (RAP) Troubleshooting
 
Iuwne10 S02 L03
Iuwne10 S02 L03Iuwne10 S02 L03
Iuwne10 S02 L03
 
Iuwne10 S01 L09
Iuwne10 S01 L09Iuwne10 S01 L09
Iuwne10 S01 L09
 
Denovo SIP VoIP Termination SBC Session Boarder Controler @ denofolab.com
Denovo SIP VoIP Termination SBC Session Boarder Controler @ denofolab.comDenovo SIP VoIP Termination SBC Session Boarder Controler @ denofolab.com
Denovo SIP VoIP Termination SBC Session Boarder Controler @ denofolab.com
 
A week with analysing RPKI status
A week with analysing RPKI statusA week with analysing RPKI status
A week with analysing RPKI status
 
4 ip services dhcp-part b
4 ip services dhcp-part b4 ip services dhcp-part b
4 ip services dhcp-part b
 
EMEA Airheads - AP Discovery Logic and AP Deployment
EMEA Airheads - AP Discovery Logic and AP DeploymentEMEA Airheads - AP Discovery Logic and AP Deployment
EMEA Airheads - AP Discovery Logic and AP Deployment
 
EMEA Airheads- Manage Devices at Branch Office (BOC)
EMEA Airheads- Manage Devices at Branch Office (BOC)EMEA Airheads- Manage Devices at Branch Office (BOC)
EMEA Airheads- Manage Devices at Branch Office (BOC)
 
Iot protocols tr 069
Iot protocols  tr 069Iot protocols  tr 069
Iot protocols tr 069
 
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
EMEA Airheads- Virtual Switching Framework- Aruba OS SwitchEMEA Airheads- Virtual Switching Framework- Aruba OS Switch
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
 
EMEA Airheads- ArubaOS - High availability with AP Fast Failover
EMEA Airheads- ArubaOS - High availability with AP Fast FailoverEMEA Airheads- ArubaOS - High availability with AP Fast Failover
EMEA Airheads- ArubaOS - High availability with AP Fast Failover
 
Free OpManager training Part 3 - Monitoring Network Performance and Network Maps
Free OpManager training Part 3 - Monitoring Network Performance and Network MapsFree OpManager training Part 3 - Monitoring Network Performance and Network Maps
Free OpManager training Part 3 - Monitoring Network Performance and Network Maps
 
4 ip services dhcp
4 ip services dhcp4 ip services dhcp
4 ip services dhcp
 
CCNA part 5 routing
CCNA part 5 routingCCNA part 5 routing
CCNA part 5 routing
 
Route Hijaking and the role of RPKI
Route Hijaking and the role of RPKIRoute Hijaking and the role of RPKI
Route Hijaking and the role of RPKI
 
Get vpn multicast for CCIE Security
Get vpn multicast for CCIE SecurityGet vpn multicast for CCIE Security
Get vpn multicast for CCIE Security
 
Webinar: How to captures and analyzes NetFlow, J-Flow and sFlow data
Webinar: How to captures and analyzes NetFlow, J-Flow and sFlow dataWebinar: How to captures and analyzes NetFlow, J-Flow and sFlow data
Webinar: How to captures and analyzes NetFlow, J-Flow and sFlow data
 
Ccna routing and switching
Ccna routing and switchingCcna routing and switching
Ccna routing and switching
 
Free OpManager training Part1- Discovery and classification season#3
Free OpManager training Part1- Discovery and classification season#3Free OpManager training Part1- Discovery and classification season#3
Free OpManager training Part1- Discovery and classification season#3
 
EMEA Airheads- ArubaOS - Rogue AP troubleshooting
EMEA Airheads- ArubaOS - Rogue AP troubleshootingEMEA Airheads- ArubaOS - Rogue AP troubleshooting
EMEA Airheads- ArubaOS - Rogue AP troubleshooting
 

Similar to DrayTek Seminar in Greece, Session 1

DrayTek RoadShow 2015 @ Portugal (Setembro) - Sessão 1
DrayTek RoadShow 2015 @ Portugal (Setembro) - Sessão 1DrayTek RoadShow 2015 @ Portugal (Setembro) - Sessão 1
DrayTek RoadShow 2015 @ Portugal (Setembro) - Sessão 1
DrayTek Corp.
 
Integrating Unified Communications and Collaboration on an Aruba Access Network
Integrating Unified Communications and Collaboration on an Aruba Access NetworkIntegrating Unified Communications and Collaboration on an Aruba Access Network
Integrating Unified Communications and Collaboration on an Aruba Access Network
Aruba, a Hewlett Packard Enterprise company
 
TP Link Load Balancer.pptx
TP Link Load Balancer.pptxTP Link Load Balancer.pptx
TP Link Load Balancer.pptx
Prakash Singh
 
F5 link controller
F5  link controllerF5  link controller
F5 link controllerJimmy Saigon
 
DrayTek RoadShow 2015 @ Portugal (Setembro) - Sessão 2
DrayTek RoadShow 2015 @ Portugal (Setembro) - Sessão 2DrayTek RoadShow 2015 @ Portugal (Setembro) - Sessão 2
DrayTek RoadShow 2015 @ Portugal (Setembro) - Sessão 2
DrayTek Corp.
 
Sangoma SBC Training Presentation
Sangoma SBC Training PresentationSangoma SBC Training Presentation
Sangoma SBC Training Presentation
Empatiq İletişim Teknolojileri AŞ.
 
Distributed IP-PBX
Distributed IP-PBX Distributed IP-PBX
OpenFlow: What is it Good For?
OpenFlow: What is it Good For? OpenFlow: What is it Good For?
OpenFlow: What is it Good For?
APNIC
 
Data Center Design Guide 4 2
Data Center Design Guide 4 2Data Center Design Guide 4 2
Data Center Design Guide 4 2Fiyaz Syed
 
PFRv3 – новое поколение технологии Performance Routing для интеллектуального ...
PFRv3 – новое поколение технологии Performance Routing для интеллектуального ...PFRv3 – новое поколение технологии Performance Routing для интеллектуального ...
PFRv3 – новое поколение технологии Performance Routing для интеллектуального ...
Cisco Russia
 
Free NetFlow Analyzer training - Getting the initial settings right
Free NetFlow Analyzer training - Getting the initial settings rightFree NetFlow Analyzer training - Getting the initial settings right
Free NetFlow Analyzer training - Getting the initial settings right
ManageEngine, Zoho Corporation
 
EMEA Airheads- Aruba Instant AP- VPN Troubleshooting
EMEA Airheads- Aruba Instant AP-  VPN TroubleshootingEMEA Airheads- Aruba Instant AP-  VPN Troubleshooting
EMEA Airheads- Aruba Instant AP- VPN Troubleshooting
Aruba, a Hewlett Packard Enterprise company
 
SWIFT: Tango's Infrastructure For Real-Time Video Call Service
SWIFT: Tango's Infrastructure For Real-Time Video Call ServiceSWIFT: Tango's Infrastructure For Real-Time Video Call Service
SWIFT: Tango's Infrastructure For Real-Time Video Call Service
Meng ZHANG
 
TCP-IP PROTOCOL
TCP-IP PROTOCOLTCP-IP PROTOCOL
TCP-IP PROTOCOL
Osama Ghandour Geris
 
Lync 2010 deep dive edge
Lync 2010 deep dive edgeLync 2010 deep dive edge
Lync 2010 deep dive edge
Harold Wong
 
P&G BT Global Services - LLD Final Revision Year 2008.
P&G BT Global Services - LLD Final Revision Year 2008.P&G BT Global Services - LLD Final Revision Year 2008.
P&G BT Global Services - LLD Final Revision Year 2008.
Kapil Sabharwal
 
Design and Deployment of Enterprise WLANs
Design and Deployment of Enterprise WLANsDesign and Deployment of Enterprise WLANs
Design and Deployment of Enterprise WLANs
Fab Fusaro
 

Similar to DrayTek Seminar in Greece, Session 1 (20)

DrayTek RoadShow 2015 @ Portugal (Setembro) - Sessão 1
DrayTek RoadShow 2015 @ Portugal (Setembro) - Sessão 1DrayTek RoadShow 2015 @ Portugal (Setembro) - Sessão 1
DrayTek RoadShow 2015 @ Portugal (Setembro) - Sessão 1
 
Integrating Unified Communications and Collaboration on an Aruba Access Network
Integrating Unified Communications and Collaboration on an Aruba Access NetworkIntegrating Unified Communications and Collaboration on an Aruba Access Network
Integrating Unified Communications and Collaboration on an Aruba Access Network
 
TP Link Load Balancer.pptx
TP Link Load Balancer.pptxTP Link Load Balancer.pptx
TP Link Load Balancer.pptx
 
F5 link controller
F5  link controllerF5  link controller
F5 link controller
 
DrayTek RoadShow 2015 @ Portugal (Setembro) - Sessão 2
DrayTek RoadShow 2015 @ Portugal (Setembro) - Sessão 2DrayTek RoadShow 2015 @ Portugal (Setembro) - Sessão 2
DrayTek RoadShow 2015 @ Portugal (Setembro) - Sessão 2
 
Chapter14ccna
Chapter14ccnaChapter14ccna
Chapter14ccna
 
Sangoma SBC Training Presentation
Sangoma SBC Training PresentationSangoma SBC Training Presentation
Sangoma SBC Training Presentation
 
Distributed IP-PBX
Distributed IP-PBX Distributed IP-PBX
Distributed IP-PBX
 
OpenFlow: What is it Good For?
OpenFlow: What is it Good For? OpenFlow: What is it Good For?
OpenFlow: What is it Good For?
 
Data Center Design Guide 4 2
Data Center Design Guide 4 2Data Center Design Guide 4 2
Data Center Design Guide 4 2
 
PFRv3 – новое поколение технологии Performance Routing для интеллектуального ...
PFRv3 – новое поколение технологии Performance Routing для интеллектуального ...PFRv3 – новое поколение технологии Performance Routing для интеллектуального ...
PFRv3 – новое поколение технологии Performance Routing для интеллектуального ...
 
Free NetFlow Analyzer training - Getting the initial settings right
Free NetFlow Analyzer training - Getting the initial settings rightFree NetFlow Analyzer training - Getting the initial settings right
Free NetFlow Analyzer training - Getting the initial settings right
 
Unit07
Unit07Unit07
Unit07
 
Vpnppt1884
Vpnppt1884Vpnppt1884
Vpnppt1884
 
EMEA Airheads- Aruba Instant AP- VPN Troubleshooting
EMEA Airheads- Aruba Instant AP-  VPN TroubleshootingEMEA Airheads- Aruba Instant AP-  VPN Troubleshooting
EMEA Airheads- Aruba Instant AP- VPN Troubleshooting
 
SWIFT: Tango's Infrastructure For Real-Time Video Call Service
SWIFT: Tango's Infrastructure For Real-Time Video Call ServiceSWIFT: Tango's Infrastructure For Real-Time Video Call Service
SWIFT: Tango's Infrastructure For Real-Time Video Call Service
 
TCP-IP PROTOCOL
TCP-IP PROTOCOLTCP-IP PROTOCOL
TCP-IP PROTOCOL
 
Lync 2010 deep dive edge
Lync 2010 deep dive edgeLync 2010 deep dive edge
Lync 2010 deep dive edge
 
P&G BT Global Services - LLD Final Revision Year 2008.
P&G BT Global Services - LLD Final Revision Year 2008.P&G BT Global Services - LLD Final Revision Year 2008.
P&G BT Global Services - LLD Final Revision Year 2008.
 
Design and Deployment of Enterprise WLANs
Design and Deployment of Enterprise WLANsDesign and Deployment of Enterprise WLANs
Design and Deployment of Enterprise WLANs
 

Recently uploaded

Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered QualitySoftware Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Inflectra
 
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
Product School
 
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
Product School
 
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
Product School
 
Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...
Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...
Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...
Ramesh Iyer
 
Mission to Decommission: Importance of Decommissioning Products to Increase E...
Mission to Decommission: Importance of Decommissioning Products to Increase E...Mission to Decommission: Importance of Decommissioning Products to Increase E...
Mission to Decommission: Importance of Decommissioning Products to Increase E...
Product School
 
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Jeffrey Haguewood
 
Key Trends Shaping the Future of Infrastructure.pdf
Key Trends Shaping the Future of Infrastructure.pdfKey Trends Shaping the Future of Infrastructure.pdf
Key Trends Shaping the Future of Infrastructure.pdf
Cheryl Hung
 
To Graph or Not to Graph Knowledge Graph Architectures and LLMs
To Graph or Not to Graph Knowledge Graph Architectures and LLMsTo Graph or Not to Graph Knowledge Graph Architectures and LLMs
To Graph or Not to Graph Knowledge Graph Architectures and LLMs
Paul Groth
 
Epistemic Interaction - tuning interfaces to provide information for AI support
Epistemic Interaction - tuning interfaces to provide information for AI supportEpistemic Interaction - tuning interfaces to provide information for AI support
Epistemic Interaction - tuning interfaces to provide information for AI support
Alan Dix
 
Monitoring Java Application Security with JDK Tools and JFR Events
Monitoring Java Application Security with JDK Tools and JFR EventsMonitoring Java Application Security with JDK Tools and JFR Events
Monitoring Java Application Security with JDK Tools and JFR Events
Ana-Maria Mihalceanu
 
Bits & Pixels using AI for Good.........
Bits & Pixels using AI for Good.........Bits & Pixels using AI for Good.........
Bits & Pixels using AI for Good.........
Alison B. Lowndes
 
GraphRAG is All You need? LLM & Knowledge Graph
GraphRAG is All You need? LLM & Knowledge GraphGraphRAG is All You need? LLM & Knowledge Graph
GraphRAG is All You need? LLM & Knowledge Graph
Guy Korland
 
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
James Anderson
 
Assuring Contact Center Experiences for Your Customers With ThousandEyes
Assuring Contact Center Experiences for Your Customers With ThousandEyesAssuring Contact Center Experiences for Your Customers With ThousandEyes
Assuring Contact Center Experiences for Your Customers With ThousandEyes
ThousandEyes
 
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 previewState of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
Prayukth K V
 
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Thierry Lestable
 
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdfFIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance
 
Generating a custom Ruby SDK for your web service or Rails API using Smithy
Generating a custom Ruby SDK for your web service or Rails API using SmithyGenerating a custom Ruby SDK for your web service or Rails API using Smithy
Generating a custom Ruby SDK for your web service or Rails API using Smithy
g2nightmarescribd
 
Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024
Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024
Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024
Tobias Schneck
 

Recently uploaded (20)

Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered QualitySoftware Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
 
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
 
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
 
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
 
Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...
Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...
Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...
 
Mission to Decommission: Importance of Decommissioning Products to Increase E...
Mission to Decommission: Importance of Decommissioning Products to Increase E...Mission to Decommission: Importance of Decommissioning Products to Increase E...
Mission to Decommission: Importance of Decommissioning Products to Increase E...
 
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
 
Key Trends Shaping the Future of Infrastructure.pdf
Key Trends Shaping the Future of Infrastructure.pdfKey Trends Shaping the Future of Infrastructure.pdf
Key Trends Shaping the Future of Infrastructure.pdf
 
To Graph or Not to Graph Knowledge Graph Architectures and LLMs
To Graph or Not to Graph Knowledge Graph Architectures and LLMsTo Graph or Not to Graph Knowledge Graph Architectures and LLMs
To Graph or Not to Graph Knowledge Graph Architectures and LLMs
 
Epistemic Interaction - tuning interfaces to provide information for AI support
Epistemic Interaction - tuning interfaces to provide information for AI supportEpistemic Interaction - tuning interfaces to provide information for AI support
Epistemic Interaction - tuning interfaces to provide information for AI support
 
Monitoring Java Application Security with JDK Tools and JFR Events
Monitoring Java Application Security with JDK Tools and JFR EventsMonitoring Java Application Security with JDK Tools and JFR Events
Monitoring Java Application Security with JDK Tools and JFR Events
 
Bits & Pixels using AI for Good.........
Bits & Pixels using AI for Good.........Bits & Pixels using AI for Good.........
Bits & Pixels using AI for Good.........
 
GraphRAG is All You need? LLM & Knowledge Graph
GraphRAG is All You need? LLM & Knowledge GraphGraphRAG is All You need? LLM & Knowledge Graph
GraphRAG is All You need? LLM & Knowledge Graph
 
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
 
Assuring Contact Center Experiences for Your Customers With ThousandEyes
Assuring Contact Center Experiences for Your Customers With ThousandEyesAssuring Contact Center Experiences for Your Customers With ThousandEyes
Assuring Contact Center Experiences for Your Customers With ThousandEyes
 
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 previewState of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
 
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
 
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdfFIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
 
Generating a custom Ruby SDK for your web service or Rails API using Smithy
Generating a custom Ruby SDK for your web service or Rails API using SmithyGenerating a custom Ruby SDK for your web service or Rails API using Smithy
Generating a custom Ruby SDK for your web service or Rails API using Smithy
 
Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024
Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024
Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024
 

DrayTek Seminar in Greece, Session 1

  • 1. 1 Connecting to the Internet Henry Lo Application Engineer Seminar
  • 2. 2 • Multi LAN Subnets / VLAN - Port-Based - Tag-Based - Inter-LAN Routing - Hybrid Example — Setup multi-subnets with APs • LAN-to-LAN VPN - PPTP and IPSec - VPN Trunk • Remote Dial-in VPN - Smart VPN Client and SSL VPN • Load-Balance/Route Policy Outline — Session 1
  • 3. 3 Outline — Session 2 • Content Security Management (CSM) - Web Content Filter with DNS Filter - APP Enforcement • User Management - Customized Login Page Logo - Create Accounts for Accommodations • AP Management - Setup, Configure, and Maintenance - Management Methods • WiFi Airtime Fairness • Bandwidth Management
  • 4. 4 Outline • Multi LAN Subnets / VLAN - Port-Based - Tag-Based - Inter-LAN Routing - Hybrid Example — Setup multi-subnets with APs • LAN-to-LAN VPN - PPTP and IPSec - VPN Trunk • Remote Dial-in VPN - Smart VPN Client and SSL VPN • Load-Balance/Route Policy
  • 5. 5 Multi LAN Subnets / VLAN • The Initial Status
  • 8. 8 Multi LAN Subnets/VLAN • A Hybrid Example - P1 in LAN1 for Administrator Management - P2~P4 in LAN2 for 3 Departments, Isolated from Each Other - P5 in LAN1 for Internal Server (e.g., FTP Server) - P6 in LAN3 for Guests
  • 9. 9 • Enable 
 LAN2 and LAN3 • Enable 
 Inter-LAN Routing Multi LAN Subnets/VLAN
  • 10. 10 • A Hybrid Example - P1 Administrator - P2, P3 Staff - P4 for AP LANA - P5 for AP LANB Multi LAN Subnets/VLAN
  • 12. 12 Outline • Multi LAN Subnets / VLAN - Port-Based - Tag-Based - Inter-LAN Routing - Hybrid Example — Setup multi-subnets with APs • LAN-to-LAN VPN - PPTP and IPSec - VPN Trunk • Remote Dial-in VPN - Smart VPN Client and SSL VPN • Load-Balance/Route Policy
  • 13. 13 Supported VPN Protocol • PPTP (TCP 1723) • L2TP (UDP 1701) • IPsec (UDP 500) • L2TP over IPsec • SSL VPN (TCP 443) • mOTP
  • 14. 14 Supported VPN Protocols None/Nice to Have/Must LAN to LAN PPTP L2TP /IPSec IPSec SSL port configurable V2960/V3900 only
  • 15. 15 LAN-to-LAN VPN • VPN for more subnets VPN 172.16.10.1/24 192.168.1.1/24 Headquarters Dial-in Branch 1 Dial-out 172.16.15.1/24 192.168.5.1/24
  • 16. VPN 16 LAN-to-LAN VPN • Hub and Spokes VPN172.16.10.1/24 192.168.1.1/24 172.16.20.1/24 Branch 2 VPN 172.16.30.1/24 VPN 172.16.40.1/24 Branch 3 Branch 4 Headquarters Branch 1
  • 17. 17 LAN-to-LAN VPN • VPN Trunk — Backup VPN 1 172.16.10.1/24 192.168.1.1/24 Dial-in Branch 1 Dial-out VPN 2 WAN 1 WAN 2 Headquarters
  • 18. 18 LAN-to-LAN VPN • VPN Trunk — Load Balance VPN 1 172.16.10.1/24 192.168.1.1/24 Dial-in Branch 1 Dial-out VPN 2 WAN 1 WAN 2 Headquarters
  • 19. 19 None/Nice to Have/Must Host to LAN PPTP L2TP /IPSec IPSec SSL port configurable PC Android Mac iOS Must DrayTek Smart VPN Client DrayTek Smart VPN Client Must Must
  • 20. 20 Remote Dial-In VPN • Smart VPN Client for Android — SSL VPN
  • 21. 21 Outline • Multi LAN Subnets / VLAN - Port-Based - Tag-Based - Inter-LAN Routing - Hybrid Example — Setup multi-subnets with APs • LAN-to-LAN VPN - PPTP and IPSec - VPN Trunk • Remote Dial-in VPN - Smart VPN Client and SSL VPN • Load-Balance/Route Policy
  • 24. 24 Configuration Page • Set Criteria - Protocol - Source / Dest IP - Port
  • 25. 25 Configuration Page • Choose Route - Interface - Gateway • Give Priority - Higher than Routing Table? - Higher than other Policies?
  • 26. 26 Configuration Page • NAT or Routing? - Regardless of the original LAN type • Failover to Interface / Policy • Gradual / Immediate Failback
  • 27. 27 Idea of Priority • Compare between Routing Table and Route Policies 100 Index Interface 1 2 Src IP Dest IP WAN2 LAN2 Any WAN1 LAN2 8.8.8.8 Priority 100 INTERNET WAN1 WAN2 LAN1 Servers LAN2 PC 150 200
  • 28. INTERNET WAN1 WAN2 LAN1 Servers LAN2 PC 28 Idea of Priority • Compare between Routing Table and Route Policies Index Interface 1 2 Src IP Dest IP 3 WAN2 LAN2 Any WAN1 LAN2 8.8.8.8 Priority 200 150 200
  • 29. INTERNET WAN1 WAN2 LAN1 Servers LAN2 PC 29 Idea of Priority • Compare between Routing Table and Route Policies Index Interface 1 2 Src IP Dest IP 3 WAN1 LAN2 8.8.8.8 WAN2 LAN2 Any Priority 200 250 250
  • 30. • Priority First, Sequence Second 30 Idea of Priority • Compare between Routing Table and Route Policies
  • 31. • Priority First, Sequence Second - With Same Priority, Sequence Matters 31 Idea of Priority • Compare between Routing Table and Route Policies
  • 33. 33 • Send SIP Traffic to the Less-Jitter WAN Load Balance
  • 34. 34 Route Policy with VPN • Local Users to Remote Server - Only Specified LAN IP are eligible to send traffic via the VPN tunnel Manager IPTV INTERNET VPNTunnel VPN TunnelVPN Server Netflix Server netflix-380.vo.llnwd.net Employees