405
Providing remote access using VPN tunnels
Multicast traffic through gateway-to-gateway IPsec tunnels
To configure multicast traffic
You must configure both security gateways and gateway-to-gateway tunnels between them.
To configure security gateway 1
1
Create a security gateway network entity for eth1, and then do the following:
■
For the address type, select interface.
■
For the address, select outside.
2
Create a security gateway network entity for the remote security gateway.
For this example, for address type, select IP address and use 10.10.20.1 as the IP address.
3
Create a host network entity using 10.10.10.1 as the address.
4
Create a host network entity using 10.10.20.1 as the address.
5
Create a gateway-to-gateway VPN tunnel and use the 10.10.10.1 host entity as the local endpoint,
and then do the following:
■
Use the 10.10.20.1 host entity as the remote endpoint.
■
Use the security gateway network entity for eth1 as the local gateway.
■
Use the security gateway network entity for the remote security gateway as the remote
gateway.
You may configure an appropriate VPN policy for use with this VPN tunnel.
To create a gateway-to-gateway tunnel for the subnets
1
Create a subnet network entity for 10.10.10.1.
2
Create a subnet network entity for 10.10.20.1.
3
Create a gateway-to-gateway VPN tunnel, and for the local endpoint, use the 10.10.10.1 subnet
entity, and then do the following:
■
Use the 10.10.20.1 subnet entity as the remote endpoint.
■
Use the security gateway network entity for eth1 as the local gateway.
■
Use the security gateway network entity for the remote security gateway as the remote
gateway.
You may configure an appropriate VPN policy for use with this VPN tunnel.
To configure security gateway 2
1
Create a security gateway network entity for eth1, and then do the following:
■
For the address type, select interface.
■
For the address, select outside.
2
Create a security gateway network entity for the remote security gateway.
For this example, for address type, select IP address and use 10.10.10.1 as the IP address.
3
Create a host network entity using 10.10.10.1 as the address.
4
Create a host network entity using 10.10.20.1 as the address.
5
Create a gateway-to-gateway VPN tunnel and use the 10.10.20.1 host entity as the local endpoint,
and then do the following:
■
Use the 10.10.10.1 host entity as the remote endpoint.
■
Use the security gateway network entity for eth1 as the local gateway.
■
Use the security gateway network entity for the remote security gateway as the remote
gateway.
You may configure an appropriate VPN policy for use with this VPN tunnel.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...