392
Providing remote access using VPN tunnels
Configuring tunnels
17
In the Confirmation panel, review the configuration of the new tunnel, and then do one of the
following:
■
If the tunnel is configured properly, click
Finish
. You will need to activate the changes before
you can use the Remote Access VPN tunnel.
■
To reconfigure any aspect of the tunnel, click
Back
until you reach the panel that needs
reconfiguration.
18
Click
Close
.
19
Optionally, do one of the following:
■
To save your configuration now and activate later, on the toolbar, click
Save
.
■
To activate your configuration now, on the toolbar, click
Activate
.
When prompted to save your changes, click
Yes
.
20
After creating the tunnel, you can use it in the following ways:
■
To specify how traffic arrives or leaves the security gateway, by including it in a rule.
■
To specify how traffic arrives at the security gateway, by including it in an address transform.
■
To simplify configuration for remote Symantec Client VPN users, by including creating a
Client VPN package.
Related information
For further information related to this topic, see the following:
■
“Remote Access Tunnel Wizard for Client VPN”
■
“Using the Remote Access Tunnel Wizard to set up clientless VPN connections”
■
■
“Controlling IP addresses with address transforms”
■
“Simplifying multiple Client VPN computer configuration”
Creating tunnels manually
For each VPN tunnel that you create, you must select a pre-configured security gateway and a network
entity local to your site, as well as a pre-configured security gateway and network entity that is remote
to your site. If the remote endpoint is a Symantec Client VPN or other third-party client, the
configuration differs, as described at the end of this section.
Your local gateway is the outside interface of your security gateway. You must create a security
gateway network entity to serve as the local gateway before you can select it for your secure tunnel.
You must also specify the remote gateway. You must create a security gateway network entity as the
remote gateway through the Network Entities tab before you can select it for your secure tunnel. While
you will likely configure few security gateway network entities to serve as local gateways, you may
configure several security gateway network entities to serve as remote gateways.
If your remote tunnel endpoint is a Symantec Client VPN that uses a mobile entity (user or user group),
then you only have to select that entity in the Remote Endpoint drop-down list for that end of the
tunnel. The Remote Gateway text box is automatically not applicable. Mobile entities act as both the
remote endpoint and remote gateway for the remote end of the tunnel.
This section describes the following tasks:
■
Manually configuring a gateway-to-gateway VPN tunnel
■
Manually configuring a Client VPN tunnel
■
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...