Issue 2.0
SV9100 Networking Manual 5-9
VPNs can be implemented in hardware or software. Single users, such as
traveling sales personnel, may have a software based VPN client on their laptop
computer. This connects back to the Head Office VPN server. For larger sites, the
VPN is typically implemented using a hardware VPN – this is often incorporated in
to a firewall solution.
The diagram below is example of how a VPN tunnel may be implemented. The
red lines in the diagram show the tunnels that are created through the Internet.
Each network can connect to the others as though they are connected with private
connections (kilostream, etc.), without the issues relating to NAT.
When IP address translation is applied to a VoIP packet, the application fails and
the communication path is broken. VoIP packets contain the IP address
information and the ports used as part of its payload. When NAT is applied, only
the header parameter is changed, not the payload data that affects the process of
data packets within the VoIP switch and terminal.
Figure 5-2 Virtual Private Network (VPN) Example
Internet
ADSL
Router
Firewall/
VPN
ADSL
Router
Firewall/
VPN
A
D
S
L
A
D
S
L
DSL / Cable / Dialup
UNIVERGE SV9100
Head Office LAN
Home Office LAN
Mobile Workers
(Software VPN Client)