Configuring VPN
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.25 Locally Managed Administration Guide | 26
Configuring Site to Site VPN with a Preshared
Secret
Introduction
In this Site to Site VPN configuration method a preshared secret is used for authentication.
Prerequisites
n
Make sure the Site to Site VPN blade is set to On and
Allow traffic from remote sites (by default)
is
selected. See
"Configuring the Site to Site VPN Blade" on page 223
.
n
The peer device that you connect to must be configured and connected to the network. If it is a DAIP
gateway, its host name must be resolvable.
Configuration
Enter a host name or IP address and enter the preshared secret information. For more information, see
"Configuring VPN Sites" on page 224
Monitoring
To make sure the VPN is working:
1.
Send traffic between the local and peer gateway.
2.
Go to
VPN
>
VPN Tunnels
to monitor the tunnel status. See
"Viewing VPN Tunnels" on page 231
.
Configuring Site to Site VPN with a Certificate
Introduction
In this Site to Site VPN configuration method a certificate is used for authentication.
Prerequisites
n
Make sure the Site to Site VPN blade is set to On and
Allow traffic from remote sites (by default)
is
selected. See
"Configuring the Site to Site VPN Blade" on page 223
.
n
The peer device that you connect to must be configured and connected to the network. If it is a DAIP
gateway, its host name must be resolvable.
n
You must reinitialize certificates with your IP address or resolvable host name. Make sure the
certificate is trusted on both sides.
n
VPN encryption settings must be the same on both sides (the local gateway and the peer gateway).
This is especially important when you use the Custom encryption option.