SonicWALL VPN Page 143
9. Select a VPN encryption method from the
Phase 2 Encryption/Authentication
menu.
Since data throughput and security are the primary concern, select
Encrypt and
Authenticate (ESP DES HMAC SHA1)
.
10. Define a
Shared Secret
. Write down this key as it is required when configuring the San
Francisco Office SonicWALL TELE3 SP.
11. Click
Add New Network...
to open the
VPN Destination Network
window and enter
the destination network addresses.
12. Enter the IP address and subnet mask of the destination network, the San Francisco office,
in the
Network
and
Subnet Mask
fields. Since NAT is enabled at the San Francisco office,
enter a private LAN IP address. In this example, enter "192.168.1.1" and subnet mask
"255.255.255.0." Click
OK
to add the destination network address.
Note
: The
Destination Network Address
must NOT be in the local network address
range. Therefore, the San Francisco and Chicago offices must have different LAN IP
address ranges.
13. Click
Advanced Settings
. Select the following boxes that apply to your SA:
•
Use Aggressive Mode
- requires half of the main mode messages to be exchanged in
Phase 1 of the SA exchange.
•
Enable Keep Alive
- if you want to maintain the current connection by listening for traffic
on the network segment between the two connections.
•
Enable Windows Networking (NetBIOS) broadcast
- if remote clients use Windows
Network Neighborhood to browse remote networks.
•
Apply NAT and firewall rules -
to apply NAT and firewall rules to the SA or just firewall
rules if in Standard mode.
•
Forward packets to remote VPNs -
if creating a “hub and spoke” network configuration
•
Enable Perfect Forward Secrecy
- if you want to add another layer of security by adding
an additional Diffie-Hellman key exchange.
•
Phase 2 DH Group
- select the type of DH key exchange in Phase 2 for
Perfect Forward
Secrecy
.
•
Default LAN Gateway
- if specifying the IP address of the default LAN route for incoming
IPSec packets for this SA. This is used in conjunction with the
Route all internet traffic
through this SA
check box.
14. Click
Update
to add the Security Association. Once the SonicWALL PRO 200 is updated, a
message confirming the update is displayed at the bottom of the browser window.
Содержание TELE3 SP
Страница 1: ...SONICWALL The TELE3 SP Administrator s Guide...
Страница 204: ...Appendices Page 203 Notes...
Страница 205: ...Page 204 SonicWALL TELE3 SP Administrator s Guide...