Main Keying Mode For An Ipsec Tunnel - McAfee SG310 Administration Manual

Utm firewall
Table of Contents

Advertisement

VPN menu features
IPSec Advanced Setup wizard

Main keying mode for an IPSec tunnel

Aggressive keying mode for an IPSec tunnel
Manual keying mode for an IPSec tunnel
Main keying mode for an IPSec tunnel
Use this procedure as guidance for creating an IPSec tunnel using the Main mode (IKE) for keying. The
configuration presented is a connection from static IP address to static IP address. At this time, IPSec VPN
offloading only is supported for static IP addresses as the remote address. The example includes specifying
an offload device.
This procedure also demonstrates how to set a next hop via the Local Interface Gateway field, which
defines the default gateway assigned by an ISP.
From the VPN menu, click IPSec. The IPSec VPN Setup page appears.
1
Click Advanced. The Tunnel Settings page appears
2
Figure 267 IPSec VPN Setup — Tunnel Settings page — Main keying
Fill in the fields.
Enter a unique Tunnel name. This example uses main_test.
a
Leave the Enable this tunnel checkbox selected.
b
From the Local Interface list, select the interface the IPSec tunnel is to go out on. The options depend
c
on what is currently configured on the appliance. For the vast majority of setups, the interface will be
the default gateway interface to the Internet.
You may want to select an interface other than the default gateway when you have configured
multiple Internet connections. If so, you must select something other than default gateway
interface from the Local Interface list. When another entry is selected, the Local Interface
Gateway field appears.
Note in
Interface, so now you can indicate an option for the Local Interface Gateway. This is the next IP
address (next hop) that IP packets are routed via to reach the remote endpoint after egress (exit)
from the previously selected IPSec interface. Available options are:
• Use Interfaces Default Gateway — Uses the default gateway for the interface selected in the
Local Interface list.
• Specify — Enter the IP address of the local gateway to use. This example uses 192.168.0.254.
268
McAfee UTM Firewall 4.0.4 Administration Guide
Figure
268, Switch A is selected in the Local Interface list, rather than Default Gateway
(Figure
267).

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sg560Sg560uSg565Sg580

Table of Contents