Adding a Tunnel
Clicking the Add button brings up the Configuration | System
| Tunneling Protocols | IPSec | LAN-to-LAN | Add screen, as shown in Figures
16-9 and 16-10. Any feature or rule with a default setting will be displayed
on the Add screen. The Modify screen is similar and is used to make a change to
an existing tunnel definition.
|
Note |
Version 4.0 added an Enable check box above the Name box.
Check this box to enable this LAN-to-LAN connection. This debugging feature
enables you to disable a LAN-to-LAN configuration without deleting it. To
disable this connection, uncheck the check box on either end of the connection.
By default, this option is enabled. |
The key features and options are as follows:
For the purposes of the scenario, the default settings are okay,
but a descriptive connection name must be entered. For the Main Office, this
might be as simple as toTacoma, while the branch office might use toMainOffice
or TakeMeHome.
Peer addresses must be added to define the peer public interface.
On the Main Office, this would be 1.10.1.1, while the branch office would enter
1.1.1.1.
The same Preshared Key must be entered on both sides. The longer
and more complex, the less likely it will be compromised. An example might be
cZ987hgy943.
The remaining choices: Authentication, Encryption, IKE Proposal,
Filter, and IPSec NAT-T must be the
same on both peers.
In the scenario, you would choose the appropriate named lists for
the Local (Main Office) and Remote (Tacoma Office)
networks.
Once the Apply button is pressed, the Configuration | Policy
Management | Traffic Management | Security Associations screen can be used to
see a list of the defined IPSec SAs. In the scenario, toTacoma would appear in
the list for the Main Office.
No Public Interfaces
The Configuration | System | Tunneling Protocols | IPSec |
LAN-to-LAN | No Public Interfaces screen is displayed if a public interface
isn’t configured on the VPN Concentrator and you try to add an IPSec LAN-to-LAN
connection. The public interface needn’t be enabled, but it must have an IP
address and the Public Interface parameter enabled. Only one VPN Concentrator
interface should designate as a public interface.