V I R T U A L P R I V A T E N E T W O R K S
Configuring Internet Key Exchange
7-30
Security Appliance User Guide
Version 3R2
7
C O N F I G U R A T I O N O F V F A
set interface br0 ip 10.0.0.100/24
set interface br0 zone untrust
set interface eth0 ip 0.0.0.0/0
set interface eth0 transparent
set interface eth0 zone trust
set interface eth1 ip 0.0.0.0/0
set interface eth1 transparent
set interface eth1 zone untrust
set route 0.0.0.0/0 interface br0 gateway 10.0.0.5
metric 1
set address trust local_lan 10.0.0.0/24
set address untrust peer_lan 172.16.10.0/24
set ike gateway gw1 address 172.16.10.100 main outgoing-
interface br0 preshare
password sec-level compatible
set vpn vpn1 gateway gw1 sec-level compatible
set policy top from trust to untrust local_lan peer_lan
any tunnel vpn
vpn1
set policy top from untrust to trust peer_lan local_lan
any tunnel vpn
vpn1
External Router IP
10.0.0.5
172.16.10.5
Default Route
0.0.0.0/0 eth br0, gateway
10.0.0.5
0.0.0.0/0eth br0, gateway
172.16.10.5
Configuration Elements
VF4000 A
VF4000 B