|
One of the enhanced services for the solution is to use an onsite managed Nortel Contivity. This unit is located on your corporate network on the private side of your firewall or a DMZ.
With this design, all your users' VPN tunnels are terminated at the onsite Contivity within the Trust.
Users can then pass straight onto the corporate LAN and can have their normal desktop login and services. This means that they have a familiar experience of access the corporate LAN.
By using a firewalled DMZ you can set a rule to force encrypted tunnels to the onsite Contivity. Unencrypted data than then be given open access onto the Corporate LAN.
In this scenario you can also allocate users IP addresses from within the origanisation's own IP address scheme. This eliminates the requirement for network address translation (NAT) again simplifying user management.
|