D-Link DFL-1000 Инструкция по эксплуатации онлайн [81/168] 42180

D-Link DFL-1000 Инструкция по эксплуатации онлайн [81/168] 42180
DFL-1000 User Manual
81
Add the destination address for the policy.
The destination address is the IP address of the remote network behind the remote VPN gateway.
If you are adding an encrypt policy for a VPN with a remote VPN client connected to the Internet, the
destination address should be the Internet address of the client computer.
Go to Firewall > Policy .
Select the policy list to which you want to add the policy.
Select New to add a new policy.
Set Source to the source address added in step 1.
Set Destination to the destination address added in step 2.
Set Action to ENCRYPT.
Service is set to ANY and cannot be changed.
Configure the ENCRYPT parameters.
VPN Tunnel
Select an AutoIKE key or Manual Key tunnel for this encrypt policy. For information about
adding VPN tunnels, see Adding an AutoIKE key VPN tunnel
and Adding a manual key VPN
tunnel.
Allow
inbound
Select Allow inbound to enable inbound users to connect to the source address.
Allow
outbound
Select Allow outbound to enable outbound users to connect to the destination address.
Inbound
NAT
The DFL-1000 NPG translates the source address of incoming packets to the IP address of the
DFL-1000 interface connected to the source address network.
Outbound
NAT
The DFL-1000 NPG translates the source address of outgoing packets to the IP address of the
DFL-1000 interface connected to the destination address network.
Use the information in Adding NAT/Route mode policies to configure the remaining policy settings.
Select OK to save the encrypt policy.
To make sure that the encrypt policy is matched for VPN connections, arrange the encrypt policy
above other policies with similar source and destination addresses in the policy list.

Содержание

Скачать