Ipsec Vpn Offloading - McAfee SG310 Administration Manual

Utm firewall
Table of Contents

Advertisement

VPN menu features

IPSec VPN offloading

maximum_retriesinfinite
Branch office UTM Firewall configuration:
##-- Custom entries MUST be added below this point
connection primary
parentipsec-tunnel-primary
parentofnetif-gre1
testifretry 2 5 ping -I 209.0.0.1 210.0.0.1 -c 3
retry_delay5
test_delay5
maximum_retriesinfinite
connection secondary
parentipsec-tunnel-secondary
parentofnetif-gre2
testifretry 2 5 ping -I 209.0.1.1 210.0.1.1 -c 3
retry_delay5
test_delay5
maximum_retriesinfinite
After editing and saving the ifmond.conf file, run the following command on both the Headquarters and
10
Branch Office UTM Firewalls to load the edits:
ipsec setup restart
The system will now be running a live failover with routing preference given to the primary connection
for traffic from the Headquarters network to the Branch Office network.
IPSec VPN offloading
IPSec VPN offloading improves overall tunnel counts and throughput by configuring additional UTM Firewall
appliances as an offload device. An IPSec offload device is another McAfee UTM Firewall appliance that has
been specifically configured to handle IPSec offloading. A single SG720 can manage about 400 IPSec
tunnels. Using the offloading configuration, the number of IPSec tunnels can be doubled, tripled, or even
quadrupled by adding more UTM Firewall appliances. This does not require any additional IP addresses. A
single Internet IP address and one UTM Firewall Management Console can administer all of the tunnels. The
offload device will handle the encryption and key processing required for all offloaded tunnels, thus greatly
reducing the load on the main gateway device.
Note:
Gateway and offload devices must be firmware 3.1.5 or later, and provide sshd services; therefore, the
SG310 model cannot function as an offload device or primary gateway for VPN tunnel offloading purposes.
Figure 315
shows offloaded tunnels from the central SG720 appliance to SG580s through the LAN
connection. It also illustrates using a multi-port switch to connect offload devices.
306
McAfee UTM Firewall 4.0.4 Administration Guide

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sg560Sg560uSg565Sg580

Table of Contents