Configuration | System | Tunneling Protocols | IPSec LAN-to-LAN | Add or Modify
7-15
VPN 3000 Concentrator Series User Guide
Note: An IP address is used with a wildcard mask to provide the desired granularity. A wildcard mask is the
reverse of a subnet mask; i.e., the wildcard mask has 1s in bit positions to ignore, 0s in bit positions to
match. For example:
0.0.0.0/255.255.255.255 = any address
10.10.1.35/0.0.0.0 = only 10.10.1.35
10.10.1.35/0.0.0.255 = all 10.10.1.nnn addresses
IP Address
Enter the IP address of the private local network on this VPN Concentrator. Use dotted decimal notation;
e.g., 10.10.0.0.

Wildcard Mask

Enter the wildcard mask for the private local network. Use dotted de cimal notation; e.g., 0.0.255.255.
The system supplies a default wildcard mask appropriate to the IP address class.
Remote Network
These entries identify the private networkon the rem ote peer VPN Concentr atorwhose hosts can use
the LAN-to-LAN connection. These entries must match those in the Local Network section on the peer
VPN Concentrator.
Network List
Click the drop-down menu button and select the configured network list that specifies the remote
network addresses. A network list is a list of network addresses that are treated as a single object. See
the Configuration | Policy Management | Traffic Management | Network Lists screens. Otherwise, you can
select:
Use IP Address/Wildcard-mask below, which lets you enter a network address.
Create new Network List (on Add screen only), which lets you create a network list of remote network
addresses. The Manager automatically opens the Configuration | System | Tunneling Protocols | IPSec
LAN-to-LAN | Add | Remote Network List screen when you click Add; see description below.
If you select a configured network list, the Manager ignores entries in the IP Address and Wildcard-mask
fields.
See the wildcard mask note above.
IP Address
Enter the IP address of the private network on the remote peer V PN Concentrator. Use dotted decimal
notation; e.g. 11.0.0.0.