Configuring Dynamic Gateway-To-Gateway Tunnels - Symantec 360R - Security Gateway SGS Administration Manual

Gateway security 300 series
Hide thumbs Also See for 360R - Security Gateway SGS:
Table of Contents

Advertisement

Establishing secure VPN connections
91
Configuring Gateway-to-Gateway tunnels
address of the security gateway changes, it re-establishes Gateway-to-Gateway
VPN tunnels with the remote gateway using the new IP address.
Gateway-to-Gateway VPN tunnel interoperability
When Symantec Gateway Security 5400 Series or Symantec Enterprise Firewall
initiates a Gateway-to-Gateway tunnel to a Symantec Gateway Security 300
Series appliance, it begins negotiation in Main Mode. The mode on the VPN
tunnel definition on the Symantec Gateway Security 300 Series VPN tunnel
definition must be Main Mode or the VPN tunnel will not establish.
Symantec Gateway Security 5400 Series and Symantec Enterprise Firewall
accept either Main Mode or Aggressive Mode Phase 1 negotiations from a
remote gateway. The Symantec Gateway Security 300 Series appliance can be
configured for Main or Aggressive Mode. The default is Main Mode. When
initiating a VPN tunnel to Symantec Gateway Security 5400 or Symantec
Enterprise Firewall, configure the Symantec Gateway Security 300 Series
appliance to use Main Mode so that if the remote end is the initiates the VPN
tunnel, it does not establish a connection.
When a non-Symantec gateway initiates a VPN tunnel to an Symantec Gateway
Security 300 Series appliance, the Symantec Gateway Security 300 Series
appliance accepts the mode set by the administrator on the tunnel definition.
When a Symantec Gateway Security 300 Series appliance initiates a VPN tunnel
to a non-Symantec security gateway, the Symantec Gateway Security 300 Series
appliance should use the mode set by the administrator on the tunnel definition;
the default setting is Main Mode. If Main Mode is not used, it may cause rekey
problems if the remote security gateway tries to rekey first.
Creating VPN tunnels to Symantec Gateway Security 5400
Series clusters
To create a VPN tunnel to a Symantec Gateway Security 5400 Series appliance
high-availability/load balancing cluster, define the VPN tunnel using the virtual
IP address of the cluster. Tunnels between Symantec Gateway 300 Series and
Symantec Gateway Security 5400 Series appliances are supported in high-
availability only.

Configuring dynamic Gateway-to-Gateway tunnels

Dynamic tunnels, also known as IKE (Internet Key Exchange) tunnels,
automatically generate authentication and encryption keys. Typically, a long
password, called a pre-shared key (also known as a shared secret), is entered.
The target security gateway must recognize this key for authentication to

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

320360

Table of Contents