Configuring The Firewall For A Vpn - Siemens RUGGEDCOM ROX II User Manual

Cli
Hide thumbs Also See for RUGGEDCOM ROX II:
Table of Contents

Advertisement

RUGGEDCOM ROX II
CLI User Guide
security firewall work-config name
Where:
• name is the name of a firewall configuration
3.
Specify the active configuration by typing:
security firewall active-config name
Where:
• name is the name of a firewall configuration
Type commit and press Enter to save the changes, or type revert and press Enter to abort.
4.
Section 5.17.6

Configuring the Firewall for a VPN

To configure the firewall for a policy-based VPN, do the following:
1.
Make sure a basic firewall has been configured. For more information about configuring a firewall, refer to
Section 5.17.3, "Adding a
2.
Make sure zones for local, network and VPN traffic have been configured. For more information about
managing zones, refer to
3.
Make sure a zone called Any exists and is of the type IPsec . For more information about managing zones,
refer to
Section 5.17.8, "Managing
4.
Configure the interface that carries the encrypted IPsec traffic. Make sure it is associated with the Any zone,
as it will be carrying traffic for all zones. For more information about associating interfaces with zones, refer
to
Section 5.17.9.3, "Associating an Interface with a
5.
Configure a host for the interface that carries the unencrypted IPsec traffic. Make sure the VPN zone is
associated with the interface. If VPN tunnels to multiple remote sites are required, make sure host entry
exists for each or collapse them into a single subnet. For more information about configuring hosts, refer to
Section 5.17.10, "Managing
6.
Configure a second host for the interface that carries the encrypted IPsec traffic. Make sure the interface is
associated with the network zone and specify a wider subnet mask, such as 0.0.0.0/0. For more information
about configuring hosts, refer to
NOTE
The VPN host must be specified before the network host so the more specific VPN zone subnet
can be inspected first.
Table: Example
Host
vpn
net
7.
Configure rules with the following parameter settings for the UDP, Authentication Header (AH) and
Encapsulation Security Payload (ESP) protocols:
Configuring the Firewall for a VPN
Firewall".
Section 5.17.8, "Managing
Zones".
Hosts".
Section 5.17.10, "Managing
Interface
W1ppp
W1ppp
Zones".
Zone".
Hosts".
Subnet
192.168.1.0/24
0.0.0.0/0
Chapter 5
Setup and Configuration
IPsec Zone
Yes
No
273

Advertisement

Table of Contents
loading

This manual is also suitable for:

Rx1500Rx1512Rx1501Rx1510Rx1511

Table of Contents