Converting An Ipsec Tunnel Configuration To The Advanced Format - McAfee SG310 Administration Manual

Utm firewall
Table of Contents

Advertisement

VPN menu features
IPSec Advanced Setup wizard
[Optional] Enter an IP address and valid netmask in the Local Network field. This is the local network
e
behind the appliance that the remote party accesses. Can be specified in either the /24 or
255.255.255.0 format.
Click Next. The Remote Endpoint Settings page appears
4
tunnel's remote endpoint settings for manual keying.
Figure 292 Setup — Remote Endpoint Settings page — Manual key mode
Enter the Internet IP address of the remote party's IPSec endpoint in the Remote party IP address
a
field.
Enter a unique, hexadecimal value for SPI (Security Parameter Index) in the SPI field.
b
• Format: 0xhex, where hex is a three-digit hexadecimal number
• Range: 0x100-0xfff
Enter the Authentication Key that applies to the remote party. It must be of the form 0xhex, where
c
hex is one or more hexadecimal digits. The hex part must be exactly 32 characters long when using
MD5 or 40 characters long when using SHA1 (excluding any underscore characters). It must use the
same hash as the appliance's authentication key.
Enter the Encryption Key that applies to the remote party. It must be of the form 0xhex, where hex
d
is one or more hexadecimal digits. The hex part must be exactly 16 characters long when using DES
or 48 characters long when using 3DES (excluding any underscore characters). It must use the same
hash as the appliance's encryption key.
[Optional] Enter an IP address and valid netmask in the Remote Network field. This is the remote
e
network behind the remote party to which the local party can have access. Can be specified in either
the
/24 or 255.255.255.0 format.
Click Finish. The tunnel is added to the Tunnel List pane.
5

Converting an IPSec tunnel configuration to the advanced format

Use Convert to Advanced to convert the tunnel's configuration from using the Quick Setup to using the
Advanced format. Subsequent modifications of the tunnel's configuration are viewed using the Advanced
format.
With the advanced format, you can take advantage of features such as VPN offloading, keying modes, RSA
Digital Key Signatures, and phase 1 & 2 rekeying for automatic tunnel renegotiation for expiring keys.
Use this procedure for general guidance when navigating the conversion wizard. For information on specific
settings, refer to the procedures within the Advanced Setup topics. See
From the VPN menu, click IPSec. The IPSec VPN Setup page appears.
1
Click the edit icon for the tunnel you want to convert to advanced format. The Tunnel Settings page
2
appears
(Figure
293).
McAfee UTM Firewall 4.0.4 Administration Guide
(Figure
292). Use this page to configure an IPSec
IPSec Advanced Setup
wizard.
283

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sg560Sg560uSg565Sg580

Table of Contents