FVS338 ProSafe VPN Firewall 50 Reference Manual
Virtual Private Networking 5-3
v1.0, September 2006
The Local WAN IP address is the address used in the IKE negotiation phase. Automatically,
the WAN IP address assigned by your ISP may display. You can modify the address to use
your FQDN; required if the WAN Mode you selected is auto-rollover.
7. Enter the Remote LAN IP Address and Subnet Mask of the remote gateway.
The information entered here must match the Local LAN IP and Subnet Mask of the remote
gateway; otherwise the secure tunnel will fail to connect.The IP address range used on the
remote LAN must be different from the IP address range used on the local LAN.
8. Click Apply to save your settings. the VPN Policies table will display showing your VPN
policy. You can click the IKE Policies tab to view the corresponding IKE Policy.
Creating a VPN Tunnel Connection to a VPN Client
You can set up multiple Gateway VPN tunnel policies through the VPN W izard. Multiple remote
VPN Client policies can also be set up through the VPN Wizard by changing the default End Point
Information settings. A remote client policy can support up to 25 clients. The remote clients must
configure the “Local Identity” field in their policy as “PolicyName<X>.fvs_remote.com”, where X
stands for a number from 1 to 25.
As an example, if the client-type policy on the router is configured with “home” as the policy
name, and if two users are required to connect using this policy, then the “Local Identity” in their
policy should be configured as “home1.fvs_remote.com” and “home2.fvs_remote.com”,
respectively.
To create a VPN Client Policy using the VPN Wizard:
1. Select VPN from the main menu and VPN Wizard from the submenu. The VPN Wizard
screen will display.
2. Select VPN Client as your VPN tunnel connection. The wizard needs to know if you are
planning to connect to a remote Gateway or setting up the connection for a remote client/PC to
establish a secure connection to this device.
3. Select a Connection Name. Enter an appropriate name for the connection. This name is not
supplied to the remote VPN Endpoint. It is used to help you manage the VPN settings.
4. Enter a Pre-shared Key. The key must be entered both here and on the remote VPN Gateway,
or the remote VPN Client. This key length should be minimum 8 characters and should not
exceed 49 characters. This method does not require using a CA (Certificate Authority).
5. The Remote Identifier Information and the Local Identifier Information will display with
the default IKE Client Policy values: fvs_remote.com for the remote end point and
fvs_local.com for the local end point.