ProSafe VPN Firewall 200 FVX538 Reference Manual
4.In the General section:
a.Enter a description name in the Policy Name Field such as “salesperson”. This name will be used as part of the remote identifier in the VPN client configuration.
b.Set Direction/Type to Responder.
c.The Exchange Mode will automatically be set to Aggressive.
5.For Local information:
d.Select Fully Qualified Domain Name for the Local Identity Type.
e.Enter an identifier in the Remote Identity Data field that is not used by any other IKE policies. This identifier will be used as part of the local identifier in the VPN client configuration.
6.Specify the IKE SA parameters. These settings must be matched in the configuration of the remote VPN client. Recommended settings are:
• Encryption Algorithm: 3DES
• Authentication Algorithm:
•
• SA Lifetime: 3600 seconds
7.Enter a
8.XAUTH is disabled by default. To enable XAUTH, select:
• Edge Device to use this router as a VPN concentrator where one or more gateway tunnels terminate. (If selected, you must specify the Authentication Type to be used in verifying credentials of the remote VPN gateways.)
• IPsec Host if you want this gateway to be authenticated by the remote gateway. Enter a Username and Password to be associated with the IKE policy. When this option is chosen, you will need to specify the user name and password to be used in authenticating this gateway (by the remote gateway).
9.If Edge Device was enabled, select the Authentication Type from the pull down menu which will be used to verify account information: User Database,
Note: If
Virtual Private Networking |
v1.0, August 2006