D-Link DFL-1000 [87/168] Adding an encrypt policy for a network to network vpn

D-Link DFL-1000 [87/168] Adding an encrypt policy for a network to network vpn
DFL-1000 User Manual
8
7
Adding source and destination addresses for a network-to-network VPN
Use the following procedures to add the network addresses to the AutoIKE key tunnel shown in Example
VPN between two internal networks. You must add a source and a destination address to both gateways.
IPSec VPN source and destination addresses
shows the information required to add the source and
destination addresses to the AutoIKE key tunnel.
IPSec VPN source and destination addresses
Field name Main Office information Branch Office information
Source Address
Address Name
Main_Office Branch_Office
IP address
192.168.1.0 192.168.2.0
Netmask
255.255.255.0 255.255.255.0
Destination Address
Address Name
Branch_Office Main_Office
IP address
192.168.2.0 192.168.1.0
Netmask
255.255.255.0 255.255.255.0
To add the Main Office and Branch Office source addresses:
Go to Firewall > Address > Internal .
Select New to add an address.
On the Main Office DFL-1000 NPG, enter the Address Name, IP Address, and NetMask, using the
Main Office source address information in IPSec VPN source and destination addresses
.
On the Branch Office DFL-1000 NPG, enter the Address Name, IP Address, and NetMask, using the
Branch Office source address information in IPSec VPN source and destination addresses
.
Select OK to save the source address.
Repeat these steps (this time selecting the External address list) to add the Main office and Branch
Office destination addresses.
Adding an encrypt policy for a network-to-network VPN
Use the following procedure to add an encrypt policy that allows IPSec VPN traffic through the firewall.
The encrypt policy associates the tunnel with the source and destination address.
Example encrypt policies
show Main Office and Branch Office encrypt policies for the VPN in Example
VPN between two internal networks.
Example encrypt policies
Field name Main Office information Branch Office information
Source
Main_Office Branch_Office
Destination
Branch_Office Main_Office
Service
ANY ANY
Action
ENCRYPT ENCRYPT
VPN Tunnel
Branch_Office_VPN Main_Office_VPN
Allow Inbound
Select Select
Allow Outbound
Select Select
Inbound NAT
Do not select. Do not select.

Содержание

Скачать