23.3 Interconnection of two private networks via the Internet (VPN tunnel)
295
Note: VPN tunnels keeps their connection (by sending special packets in regular time intervals)
even if no data is transmitted. This feature protects tunnels from disconnection by other
firewalls or network devices between ends of tunnels.
Traffic Policy Settings for VPN
Oncethe VPN tunnel is created, itis necessary to allow traffic between the LAN and the network
connected by the tunnel and to allow outgoing connection for the Kerio VPN service (from
the firewall to the Internet). If basic traffic rules are already created by the wizard (refer to
chapter 23.2), simply add a corresponding VPN tunnel into the Local Traffic rule and the Kerio
VPN service to the Firewall traffic. The resulting traffic rules are shown at figure 23.11.
Figure23.11 TrafficPolicy Settings for VPN
Note:
1. To keep examples in this guide as simple as possible, it is supposed that the Firewall traffic
rule allows to access any service at the firewall (see figure 23.12). Under these conditions,
it is not necessary to add the Kerio VPN service to the rule.
Figure23.12 Commontraffic rules for VPN tunnel