FVS338 ProSafe VPN Firewall 50 Reference Manual
Virtual Private Networking 5-3
v1.0, March 2008
The Local WAN IP address is the address used in the IKE negotiation phase. Automatically,
the WAN IP address assigned by your ISP may display. You can modify the address to use
your FQDN; required if the WAN Mode you selected is auto-rollover.
7. Enter the Remote LAN IP Address and Subnet Mask of the remote gateway.
The information entered here must match the Local LAN IP and Subnet Mask of the remote
gateway; otherwise the secure tunnel will fail to connect.The IP address range used on the
remote LAN must be different from the IP address range used on the local LAN.
8. Click Apply to save your settings. the VPN Policies table will display showing your VPN
policy. You can click the IKE Policies tab to view the corresponding IKE Policy.

Creating a VPN Tunnel Connection to a VPN Client

You can set up multiple Gateway VPN tunnel policies through the VPN Wizard. Multiple remote
VPN Client policies can also be set up through the VPN W izard by changing the default End Point
Information settings. A remote client policy can support up to 25 clients. The remote clients must
configure the “Local Identity” field in their policy as “PolicyName.fvs_remote.com”.
To create a VPN Client Policy using the VPN Wizard:
1. Select VPN from the main menu and VPN W i zard from the submenu. The VPN Wizard
screen will display.
2. Select VPN Client as your VPN tunnel connection. The wizard needs to know if you are
planning to connect to a remote Gateway or setting up the connection for a remote client/PC to
establish a secure connection to this device.
3. Select a Connection Name. Enter an appropriate name for the connection. This name is not
supplied to the remote VPN Endpoint. It is used to help you manage the VPN settings.
4. Enter a Pre-shar ed Key. The key must be entered both here and on the remote VPN Gateway,
or the remote VPN Client. This key length should be minimum 8 characters and should not
exceed 49 characters. This method does not require using a CA (Certificate Authority).
5. The Remote Identifier Information and the Local Identifier Information will display with
the default IKE Client Policy values: fvs_remote.com for the remote end point and
fvs_local.com for the local end point.
6. Click Apply. The VPN Client screen will display showing that the VPN Client has been
enabled. Click the IKE Policies tab to view the corresponding IKE Client Policy.