SonicWALL VPN Page 121
7. Select
Encrypt and Authenticate (ESP DES HMAC MD5)
from the
Phase 2
Encryption/Authentication
menu.
8. Create and enter a
Shared Secret
in the
Shared Secret
field or use the
Shared Secret
automatically generated by the SonicWALL. The
Shared
Secret
should consist of a
combination of letters and numbers rather than the name of a family member, pet, etc. It
is also case-sensitive.
9. Click
Advanced Settings
to open the window. Select any of the following boxes that apply
to your SA:
•
Require authentication of VPN clients via XAUTH
- requires VPN client authentication
via a RADIUS server.
•
Apply NAT and firewall rules
- to apply NAT and firewall rules to the SA or just firewall
rules if in Standard mode.
•
Forward packets to remote VPNs
- if creating a “hub and spoke” network.
•
Enable Perfect Forward Secrecy
- if adding an additional layer of security using a
second Diffie_Hellman key exchange.
•
Phase 2 DH Group
- generates a additional key exchange.
•
Default LAN Gateway
- The
Default LAN Gateway
field allows the network
administrator to specify the IP address of the default LAN route for incoming IPSec packets
for this SA.
Note
: It is not necessary to configure the Advanced Settings to get the VPN connection
working between the SonicWALL and the VPN client. You can configure the Advanced
Settings later, and then re-import the SA into the VPN Client.
10. Click
Update
to enable the changes.
To export the
Group VPN
settings to remote VPN clients, click on
Export
next to
VPN Client
Configuration File
. The security file can be saved to a floppy disk or e-mailed to a remote
VPN client. The
Shared
Secret
, however, is not exported, and must be entered manually by
the remote VPN client. Also, the SA must be enabled to export the configuration file.
Note
: You must use the
Group VPN Security Association
even if you have only one VPN
client to deploy, and you want to use IKE using Pre-shared Secret for your SA. The
Group VPN
Security Association
defaults to the
Simple Configuration
previously available in firmware
version 5.1.1.
Installing the VPN Client Software
1. When you register your SonicWALL or SonicWALL VPN Upgrade, a unique VPN client serial
number and link to download the SonicWALL VPN Client zip file is displayed.
2. Unzip the SonicWALL VPN Client zip file.
3. Double-click
setup.exe
and follow the VPN client setup program step-by-step instructions.
Enter the VPN client serial number when prompted.
Содержание TELE3 SP
Страница 1: ...SONICWALL The TELE3 SP Administrator s Guide...
Страница 204: ...Appendices Page 203 Notes...
Страница 205: ...Page 204 SonicWALL TELE3 SP Administrator s Guide...