IPSec Configuration

Table 7–3: IPSec Security Association Configuration Parameters (Continued)

Parameter

Description

 

 

 

 

Tunnel Setup

 

 

 

Local Networks

Select one of the following methods to determine what local traffic

 

may access or be accessed from the VPN tunnel. This method is

 

only used for IPSec tunnel mode connections:

 

• IP Address Group (configure from Network > Configuration >

 

IP Address Groups) - use this option if traffic allowed over the

 

VPN tunnel is from multiple IP subnets.

 

• IP Subnet

 

• IP Range

 

• Peer uses tunnel as default route

 

Select this method if you have want the IPSec tunnel to be used as

 

the default route for the device.

 

• Local addresses assigned by DHCP through this tunnel

 

Select this method if the connection will be used to connect two X

 

family devices that have been configured to use DHCP Relay over

 

VPN.

 

 

Remote Networks

Select one of the following methods to determine what traffic

 

should be routed over the VPN tunnel. This method is only used for

 

IPSec tunnel mode connections:

 

• IP Address Group (configure from Network > Configuration >

 

IP Address Groups) - use this option if traffic allowed over the

 

VPN tunnel is from multiple IP subnets.

 

• IP Subnet

 

• IP Range

 

• Peer uses tunnel as default route

 

Select this method if you have want the IPSec tunnel to be used as

 

the default route for the device.

 

• Local addresses assigned by DHCP through this tunnel

 

Select this method if the connection will be used to connect two X

 

family devices that have been configured to use DHCP Relay over

 

VPN.

 

 

X Family LSM User’s Guide V 2.5.1

193