Virtual Private Network (VPN)
The VPN tab allows you to define Virtual Private Network (VPN) gateways.
Defining VPN gateways using this mechanism simplifies the creation of
VPNs that include more than two gateways.
Note: Each gateway in this
type of configuration must be able to connect to the other ones
direcly--without going through another gateway.
Setting up a VPN requires the following operations:
-
Defining the VPN gateways.
-
Adding a rule for the VPN.
Defining VPN Gateways
Use the VPN tab on the Policy Edit page to define and edit the VPN
gateways. The meanings and uses of the specific fields in the VPN dialog
are as follows:
-
Rule Index (Optional) Assigns a number to a rule. By default, this field
displays a number one greater than the last rule (indicating
this rule will be placed bottom of the list. If you type a
lower number, the new rule will be inserted into the specified
position in the list, and the rules currently in the
configuration will be renumbered.
-
Name Specifies the name of the VPN to which this gateway belongs. Note: Type the same name in the Name field
for each gateway that you include in the VPN.
-
Address Specifies the machine to be included in the VPN.
-
Certificate Specifies the name of the certificate for this VPN gateway.
-
Key Algorithm Specifies the key algorithm the VPN will use. Note: All
gateways in the same VPN must use the same key algorithm.
-
Data Algorithm Specifies the data algorithm the VPN will use. Note: All
gateways in the same VPN must use the same data algorithm.
-
MAC Algorithm Specifies the MAC algorithm the VPN will use. Note: All
gateways in the same VPN must use the same MAC algorithm.
-
Tunnel Address Specifies the destination address on the outer (unencrypted)
IP packet to which tunnel packets are sent.
-
Description (Optional) Provides a short description of the VPN gateway.
Adding a Rule
After you define the gateways in your VPN,
add a
Packet Filter rule for this
VPN. Use the
Packet Filtering tab on the Policy Edit
page to add VPN rules
When you add a packet filter rule for VPN:
-
Leave the Screen field empty.
-
Specify SECURE for the packet
filter action.
-
Enter the name of the VPN in the VPN field.
Note:
Any addresses may be used in VPN rules, however only addresses that intersect
with a VPN Gateway and the address specified in the rule will apply. Therefore,
the simplest way to have all Screens in the VPN communicate (without creating
an Address Group that explicitly contains them) is to use "*" "*" as the
Addresses in the rule.