268
McAfee UTM Firewall 4.0.4 Administration Guide
VPN menu features
IPSec Advanced Setup wizard
•
Main keying mode for an IPSec tunnel
•
Aggressive keying mode for an IPSec tunnel
•
Manual keying mode for an IPSec tunnel
Main keying mode for an IPSec tunnel
Use this procedure as guidance for creating an IPSec tunnel using the Main mode (IKE) for keying. The
configuration presented is a connection from static IP address to static IP address. At this time, IPSec VPN
offloading only is supported for static IP addresses as the remote address. The example includes specifying
an offload device.
This procedure also demonstrates how to set a next hop via the Local Interface Gateway field, which
defines the default gateway assigned by an ISP.
1
From the VPN menu, click IPSec. The IPSec VPN Setup page appears.
2
Click Advanced. The Tunnel Settings page appears (
Figure 267
).
Figure 267 IPSec VPN Setup — Tunnel Settings page — Main keying
Fill in the fields.
a
Enter a unique Tunnel name. This example uses main_test.
b
Leave the Enable this tunnel checkbox selected.
c
From the Local Interface list, select the interface the IPSec tunnel is to go out on. The options depend
on what is currently configured on the appliance. For the vast majority of setups, the interface will be
the default gateway interface to the Internet.
You may want to select an interface other than the default gateway when you have configured
multiple Internet connections. If so, you must select something other than default gateway
interface from the Local Interface list. When another entry is selected, the Local Interface
Gateway field appears.
Note in
Figure 268
, Switch A is selected in the Local Interface list, rather than Default Gateway
Interface, so now you can indicate an option for the Local Interface Gateway. This is the next IP
address (next hop) that IP packets are routed via to reach the remote endpoint after egress (exit)
from the previously selected IPSec interface. Available options are:
• Use Interfaces Default Gateway — Uses the default gateway for the interface selected in the
Local Interface list.
• Specify — Enter the IP address of the local gateway to use. This example uses
192.168.0.254
.
Содержание SG310
Страница 1: ...McAfee UTM Firewall Administration Guide version 4 0 4...
Страница 10: ...10 McAfee UTM Firewall 4 0 4 Administration Guide...
Страница 127: ...McAfee UTM Firewall 4 0 4 Administration Guide 127 Network Setup menu options DHCP Server Figure 130 DHCP Addresses page...
Страница 148: ...148 McAfee UTM Firewall 4 0 4 Administration Guide Network Setup menu options SIP...
Страница 238: ...238 McAfee UTM Firewall 4 0 4 Administration Guide Firewall menu options Antispam TrustedSource...
Страница 372: ...372 McAfee UTM Firewall 4 0 4 Administration Guide System menu features Advanced menu...
Страница 410: ...410 McAfee UTM Firewall 4 0 4 Administration Guide Index...
Страница 411: ......
Страница 412: ...700 2237A00...