VPN
Configuring the Site-to-Site VPN
Cisco ISA500 Series Integrated Security Appliance Administrator Guide
249
8
•
IPSec Policy Enable:
Click
On
to enable the IPSec VPN policy, or click
Off
to create only the IPSec VPN policy. For an enabled IPSec VPN policy, the
VPN tunnel can be connected by manually clicking
Connect
or be triggered
by traffic.
•
Remote Type:
Choose one of the following types for the remote peer:
-
Static IP:
Choose this option if the remote peer uses a static IP address.
Enter the IP address
of the remote peer in the
Address
field.
-
Dynamic IP:
Choose this option if the remote peer uses a dynamic IP
address.
-
FQDN (Fully Qualified Domain Name):
Choose this option to use the
domain name of the remote network, such as vpn.company.com. Enter
the domain name of the remote peer in the
Address
field.
For the example as illustrated in
Figure 10
, the remote site, Site B, has a
public IP address of 209.165.200.236. You should choose
Static IP
for the
type, and enter 209.165.200.236 in the
Address
field.
•
Authentication Method:
Choose the authentication method for the IPSec
VPN policy.
-
Preshare Key:
If you choose this option, enter the desired value that the
peer device must provide to establish a connection. The same pre-
shared key has to be entered on the remote peer device.
-
Certificate:
If you choose this option, choose a local certificate and a
remote certificate for authentication. On the remote clients, the selected
local certificate should be set as the remote certificate, and the selected
remote certificate should be set as the local certificate. If the certificate
is not in the list, go to the
Device Management -> Certificate
Management
page to import the certificates. See
Certificates for Authentication, page 310
•
WAN Interface:
Choose the WAN interface that the traffic passes through
over the IPSec VPN tunnel.
•
Local Network:
Choose the IP address of the local network. If you want to
configure the zone access control settings for Site-to-Site VPN, choose
Any
for the local network.
•
Remote Network:
Choose the IP address of the remote network. You must
know the IP address of the remote network before connecting the IPSec
VPN tunnel.