ProSecure Unified Threat Management (UTM) Appliance

3.Complete the fields, select the radio buttons, and make your selections from the drop-down lists as explained in the following table:

Table 72. Add IKE Policy screen settings

Setting

Description

 

 

 

 

Mode Config Record

 

 

 

 

 

Do you want to use

Specify whether the IKE policy uses a Mode Config record. For information about

Mode Config Record?

how to define a Mode Config record, see Mode Config Operation on page 312.

 

Select one of the following radio buttons:

 

Yes. IP addresses are assigned to remote VPN clients. You need to select a

 

Mode Config record from the drop-down list.

 

Because Mode Config functions only in Aggressive mode, selecting the Yes

 

radio button sets the tunnel exchange mode to Aggressive mode and disables

 

the Main mode. Mode Config also requires that both the local and remote

 

endpoints are defined by their FQDNs.

 

No. Disables Mode Config for this IKE policy.

 

 

 

 

Select Mode

From the drop-down list, select one of the Mode Config

 

Config Record

records that you defined on the Add Mode Config Record

 

 

screen (see Configure Mode Config Operation on the UTM on

 

 

page 312).

 

 

Note: Click the View Selected button to open the Selected

 

 

Mode Config Record Details pop-up screen.

 

 

 

General

 

 

 

 

 

Policy Name

A descriptive name of the IKE policy for identification and management purposes.

 

Note: The name is not supplied to the remote VPN endpoint.

 

 

Direction / Type

From the drop-down list, select the connection method for the UTM:

 

Initiator. The UTM initiates the connection to the remote endpoint.

 

Responder. The UTM responds only to an IKE request from the remote

 

endpoint.

 

 

Both. The UTM can both initiate a connection to the remote endpoint and

 

respond to an IKE request from the remote endpoint.

 

 

Exchange Mode

From the drop-down list, select the mode of exchange between the UTM and the

 

remote VPN endpoint:

 

Main. This mode is slower than the Aggressive mode but more secure.

 

Aggressive. This mode is faster than the Main mode but less secure.

 

Note: If you specify either an FQDN or a user FQDN name as the local ID or

 

remote ID (see the Identifier Type sections later in this table), the Aggressive mode

 

is automatically selected.

Local

 

 

 

 

 

Select Local Gateway

Select a WAN interface from the drop-down list to specify the WAN interface for

(multiple WAN port

the local gateway.

 

models only)

 

 

 

 

 

Virtual Private Networking Using IPSec, PPTP, or L2TP Connections

296

Page 296
Image 296
NETGEAR UTM5EW-100NAS manual Add IKE Policy screen settings, 296, Setting Description Mode Config Record, General, Local