. . . . .
V I R T U A L P R I V A T E N E T W O R K S
Configuring Internet Key Exchange
Version 3R2
Security Appliance User Guide
7-21
Routing
set route trust route 0.0.0.0/0 interface eth1 gateway
162.198.10.254
Policies
set policy top name vpnto_sanfrancisco from trust to
untrust ny_local sf_destination any tunnel vpn sfo_nyo
set policy top name vpnfrom_sanfrancisco from untrust to
trust sf_destination ny_local any tunnel vpn sfo_nyo
save
G U I E X A M P L E : N E W Y O R K O F F I C E U S I N G I K E
Interfaces
1
Network > Interface > Edit (for ethernet0)
2
Enter the following, then click
Apply
:
Zone Name: Trust
IP Address/Netmask: 192.168.100.1/24
Interface Mode: NAT
3
Network > Interface > Edit (for eth1)
4
Enter the following, then click
Apply
:
Zone Name: Untrust
IP Address/Netmask: 162.198.10.1/24
Addresses
1
Objects > Address Objects > Add Object
2
Enter the following, then click
Apply
:
Name: ny_local
IP Address/Netmask: 192.168.100.0/24
Zone: Trust