D-Link DFL-1000 [88/168] Autoike key vpn for remote clients

D-Link DFL-1000 [88/168] Autoike key vpn for remote clients
DFL-1000 User Manual
8
8
Outbound NAT
Do not select. Do not select.
To add the encrypt policy:
Go to Firewall > Policy .
Select Int
->
Ext.
Select New to add a new policy.
On the Main Office DFL-1000 NPG set Source and Destination to the Main Office Source and
Destination shown in Example encrypt policies
.
On the Branch Office DFL-1000 NPG set Source and Destination to the Branch Office Source and
Destination shown in Example encrypt policies
.
Set Action to ENCRYPT.
Service is set to ANY and cannot be changed.
On the Main Office DFL-1000 NPG set VPN Tunnel to Branch_Office_VPN.
On the Branch Office DFL-1000 NPG set VPN Tunnel to Main_Office_VPN.
Select Allow Inbound and Allow Outbound to allow two-way communication through the VPN.
You can also select Log Traffic and Web filter for encrypt policies.
Select OK to save the policy.
AutoIKE key VPN for remote clients
A remote VPN client can be any computer connected to the Internet with a static IP address and running
VPN client software that uses IPSec and AutoIKE key. The following procedures show an example
configuration for an IPSec AutoIKE key VPN between an internal network and a remote VPN client.
Example VPN between a main office internal network and a remote client
The example shows a remote client on the Internet using IPSec VPN to connect to an address on the
internal network. You can also configure an encrypt policy so that:
a client on the Internet can connect to an address on the DMZ network,
a client on the DMZ network can connect to an address on the internal network.
This section describes:

Содержание

Скачать