SonicWALL Internet Security Appliance Guide Page 141
5. Enter the SonicWALL GX250 WAN IP Address in the
IPSec Gateway Address
field. This address must be valid, and is the SonicWALL GX250 NAT Public Address,
or "216.0.0.20."
6. Enter "86,400" in the
SA Life time (secs)
field to renegotiate keys daily.
7. Select the encryption algorithm from the
Encryption Method
menu. The San
Francisco office
Encryption Method
must match Chicago, so
ARC Four
must be
selected.
8. Enter the same
Shared Secret
used in the Chicago Office SonicWALL GX250 into
the SonicWALL TELE2
Shared Secret
field.
9. Click
Add New Network...
to open the
VPN Destination Network
window and
define the destination network addresses.
10. Enter the IP address and subnet mask of the destination network, the Chicago of-
fice, in the
Network
and Subnet Mask fields. Since NAT is enabled at the Chicago
office, enter a private LAN IP address. In this example, enter "192.168.2.1" and
subnet mask "255.255.255.0.”
11. Click
Advanced Settings.
12. Check
Enable Keep Alive
if you want the SA to check for an active VPN tunnel
while the tunnel is connected.
13. Check
Enable Perfect Forward Secrecy
for added security.
14. Check
Enable Windows Networking (NetBIOS) broadcast
to allow the re-
mote site access to network resources by browsing the Windows Network Neigh-
borhood.
15. Check
Apply NAT and firewall rules
if applicable.
16. Check
Forward Packets to Remote VPNs
if configuring a “hub and spoke”net-
work.
17. Check
Route all Internet Traffic through this SA
if configuring a remote site
without access to the Internet via the VPN tunnel.
18. Enter the
Default LAN Gateway if Route all Internet traffic
through this SA
is checked.
19. Click OK to close the
Advanced Settings
window.
20. Click
Update
to add the remote network and close the
VPN Destination Net-
work
window. Once the SonicWALL TELE2 has been updated, a message confirm-
ing the update is displayed at the bottom of the browser window.
Note
: Since Window Networking (NetBIOS) has been enabled, users may view remote
computers in their Windows Network Neighborhood. Users may also access resources
on the remote LAN by entering servers' or workstations remote IP addresses.
integrated_manual.book Page 141 Wednesday, June 13, 2001 6:21 PM