Remote WLAN Design
The remote WLAN design uses remote VPN connectivity based on either software- or hardware-terminated IPSec VPNs to a central site. Refer to Chapter 17, "Designing Remote SAFE Networks," for further details on the two remote IPSec VPN options discussed here.
Remote Software-Based VPN WLAN Design
The remote software-based VPN WLAN design is recommended when security is focused on the wireless device or user. Secure connectivity is provided through the use of a personal firewall on the user's device and through the IPSec VPN to the corporate resource.Wireless connectivity is focused primarily on just providing an IP path to the headend VPN gateway.Figure 20-10 illustrates the remote software VPN WLAN design.
Figure 20-10. Remote Software VPN WLAN Design
[View full size image]

Remote Hardware-Based VPN WLAN Design
The remote hardware-based VPN WLAN design is recommended when security is focused on the remote LAN. Wireless users authenticate to the WLAN using EAP, while the LAN has a hardware-based IPSec connection to the headend VPN gateway.Figure 20-11 illustrates the remote hardware VPN wireless LAN design.
Figure 20-11. Remote Hardware VPN Wireless LAN Design
[View full size image]
