Chapter 3 Setting up the Nortel VPN Router 1010, 1050, and 1100 63Nortel VPN Router Configuration — Basic Features• Set the Text Pre-Shared Key to the same name as central office tunnelpassword.• Set Dynamic Routing to enabled.• Set RIP to enabled.After the central office setup and the BOQS are complete, the Nortel VPNRouter1010, 1050, or 1100 is directly accessible from the central office. Thismeans that there is just one hop between the central office and the branch office.RIP propagates routes to this subnet across the tunnel created by BOQS.You must have at least two more IP addresses than IP workstations on the NortelVPN Router 1010, 1050, or 1100 private network. The first address from thesubnet is assigned to the private interface of the branch office switch and thesecond address becomes the management IP address of the switch. Each branchoffice must be in its own subnet.Table 5 shows how offices with approximately 50 workstations can each havesubnets assigned.Service provider environmentService providers generally have an isolated NOC from which all devices aremanaged. The addressing scheme could be different from a central office andrequire a separate designated tunnel to configure the Nortel VPN Router 1010/1050/1100 series of switches.Table 5 Subnet assignmentsPrivateNetwork IPaddressPrivate NetworkIP MaskNortel VPNRouter1010/1050/1100 PrivateInterface AddressNortel VPNRouter1010/1050/1100 ManagementInterface AddressBO WorkstationsAddresses (assignedby DHCP Server)200.1.1.0 255.255.255.192 200.1.1.1 200.1.1.2 From 200.1.1.3 to200.1.1.62200.1.1.64 255.255.255.192 200.1.1.65 200.1.1.66 From 200.1.1.67 to200.1.1.126200.1.1.128 255.255.255.192 200.1.1.129 200.1.1.130 From 200.1.1.131 to200.1.1.190