Page 140 SONICWALL VPN
8. Define a
Shared Secret
. Write down this key as it is required when configuring
the San Francisco Office SonicWALL TELE2.
9. Click
Add New Network...
to open the
VPN Destination Network
window and
enter the destination network addresses.
10. Enter the IP address and subnet mask of the destination network, the San Francis-
co office, in the
Network
and
Subnet Mask
fields. Since NAT is enabled at the
San Francisco office, enter a private LAN IP address. In this example, enter
"192.168.1.1" and subnet mask "255.255.255.0."
Note
: The
Destination Network Address
must NOT be in the local network's
address range. Therefore, the San Francisco and Chicago offices must have different
LAN IP address ranges.
11. Click
Advanced Settings.
12. Check
Enable Keep Alive
if you want the SA to check for an active VPN tunnel
while the tunnel is connected.
13. Check
Enable Perfect Forward Secrecy
for added security.
14. Check
Enable Windows Networking (NetBIOS) broadcast
if the remote site
is allowed access to network resources by browsing the Windows Network Neigh-
borhood.
15. Check
Apply NAT and firewall rules
if applicable.
16. Check
Forward Packets to Remote VPNs
if configuring a “hub and spoke”net-
work.
17. Check
Route all Internet Traffic through this SA
if configuring a remote site
without access to the Internet via the VPN tunnel.
18. Enter the
Default LAN Gateway if Route all Internet traffic
through this SA
is checked.
19. Click OK to close the
Advanced Settings
window.
20. Click
Update
to add the remote network and close the
VPN Destination Net-
work
window. Once the SonicWALL GX250 is updated, a message confirming the
update is displayed at the bottom of the browser window.
Configuring a SonicWALL TELE2 in San Francisco
1. Enter the SonicWALL TELE2
Unique Firewall Identifier
in the
VPN Summary
window, in this example, "San Francisco Office."
2. Select
-Add New SA-
from the
Security Association
menu.
3. Select
IKE using pre-shared secret
from the IPSec Keying Mode menu.
4. Enter the SonicWALL GX250
Unique Firewall Identifier
in the SonicWALL TELE2
Name
field, in this example, "Chicago Office."
integrated_manual.book Page 140 Wednesday, June 13, 2001 6:21 PM