Routing
At the service provider site, you can configure corporate routing between the AVG and its private network. At the customer site, you can locate each IP Office system on the private side of a corporate router. The corporate router does not require configuration changes for the SSL VPN service to work.
IP Office forwards data to the AVG over the SSL VPN service using split tunneling routes or static routes. You must use one of these options to send traffic through the SSL VPN tunnel:
let IP Office dynamically install split tunneling routes when the SSL VPN service connects with AVG, and remove these routes when the service disconnects
configure a static route in IP Office Manager
Split tunneling
When you install and configure AVG, you can add split network subnets or host addresses for a group. The IP Office system learns the routing information for the tunnel dynamically when the SSL VPN service successfully connects with the AVG. The split networks routes are removed when the SSL VPN service disconnects from AVG.
For information about configuring split tunneling on the AVG using Net Direct, see the Avaya VPN Gateway Administration Guide (NN46120-105) and the Avaya VPN Gateway BBI Application Guide (NN46120-102). For information about configuring split tunneling using the command line interface, see CLI Application Guide (NN46120-101).
Static routes
As an alternative to split tunneling, you can configure a static route directly on the IP Office system. When you configure a static route, the system uses the IP route information configured in Manager to determine the destination for forwarded traffic. You must define the SSL VPN service as the destination.
Use a static route when:
split tunneling routes are not advertised by the AVG and you need to send traffic through the tunnel
the SSL VPN service is not connected to the AVG and you want to queue traffic to be forwarded through the tunnel when the connection is restored; in this case, IP Office temporarily queues a small number of packets that trigger the connection when the SSL VPN is in-service but disconnected
You can configure multiple static routes on the IP Office system.