V I R T U A L P R I V A T E N E T W O R K S
Configuring Manual Key VPN Implementations
7-14
Security Appliance User Guide
Version 3R2
7
VPN
set vpn to_newyork manual 1230 1230 gateway 4.4.4.1
outgoing-interface eth1 esp-aes128 key 1111222233334444
auth sha-1 key 11112222333344445555666677778888
Routing
set route trust route 0.0.0.0/0 interface eth1 gateway
4.4.4.254
Policies:
set policy top name vpnto_newyork from trust to untrust
sfo New York any tunnel vpn sfo_nyo
set policy top name vpnfrom_newyork from untrust to
trust New York sfo any tunnel vpn sfo_nyo
save
G U I E X A M P L E : M A N U A L K E Y V P N I M P L E M E N T A T I O N , S A N
F R A N C I S C O O F F I C E
Interfaces
1
Network > Interface > Edit (for ethernet0)
2
Enter the following, then click
Apply
:
Zone Name: Trust
IP Address/Netmask: 10.0.0.0/24
Interface Mode: NAT
3
Network > Interface > Edit (for eth1): Enter the following, then click
Apply
:
Zone Name: Untrust
IP Address/Netmask: 4.4.4.1/24
Addresses
1
Objects > Address Objects > Add Object
2
Enter the following, then click
Apply
:
Name: SFO