Peers" Tab - Stormshield SN series Configuration Manual

Hide thumbs Also See for SN series:
Table of Contents

Advertisement

Encryption profile This option allows selecting the protection model associated with your VPN policy, from the
Config mode
Comments
You can only use and create a single mobile (roadwarrior) configuration per IPSec profile.
Peers can be applied to all profiles. As a result, only one authentication type can be used at
a time for the mobile configuration.
Checking the policy in real time
The window for editing IPSec policy rules has a "Check policy" field (located below the table),
which warns the administrator whenever there are inconsistencies or errors in the rules created.
Example:
IPSec policy.

"Peers" tab

This tab consists of two sections:
Left: the list of IPSec VPN and mobile IPSec VPN peers.
l
Right: Information about the selected peer.
l
Page 169/448
choice of 3 preconfigured profiles: StrongEncryption, GoodEncryption and Mobile. Other
profiles can be created or modified in the tab Encryption profiles.
This column makes it possible to activate "Config mode", which is disabled by default. This
allows distributing the traffic endpoint IP address to the peer
NOTES
1. If you choose to activate this mode, you will need to select an object other
than "Any" as the remote network.
2. With config mode, only one policy can be applied per profile.
The Edit button allows entering the parameters of the IPSec Config mode:
DNS Server
This field determines the host (DNS server) that will be used by mobile
clients, for DNS resolutions. You can select it or create it in the object
database. This field is empty by default.
List of
The client will use the DNS server selected earlier, only for domains specified
domains
in this table. For other domains, the client will continue to use its DNS server
used in
(s). Therefore generally internal domain names are involved.
Config mode
Example: In the case of the domain "company.com", if an iPhone attempts to
connect to "www.company.com" or "intranet.company.com" it will use the
DNS server specified above. However, if it attempts to contact
"www.google.fr", it will continue to use its older DNS servers.
Description given of the VPN policy.
REMARK
[gateway policy at line 2] - Different IKE versions cannot be used in the same
SNS - USER CONFIGURATION MANUAL V.3
sns-en-user_configuration_manual-v3 - Copyright © Stormshield 2016
IPSEC VPN

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents