Reference Manual for the ProSafe VPN Firewall FVS114
6-16
Advanced Virtual Private Networking
202-10098-01, April 2005
The IKE Phase 2 parameters used in Scenario 1 are:
•
TripleDES
•
SHA-1
•
ESP tunnel mode
•
MODP group 2 (1024 bits)
•
Perfect forward secrecy for rekeying
•
SA lifetime of 3600 seconds (one hour) with no kilobytes rekeying
•
Selectors for all IP protocols, all ports, between 10.5.6.0/24 and 172.23.9.0/24, using IPv4
subnets
FVS114 Scenario 1: FVS114 to Gateway B IKE and VPN Policies
Note
: This scenario assumes all ports are open on the FVS114. You can verify this by reviewing
the security settings as seen in the
Figure 4-2
on
page 4-4
.
Figure 6-6: LAN to LAN VPN access from an
FVS114
to an
FVS114
Use this scenario illustration and configuration screens as a model to build your configuration.
1. Log in to the FVS114 labeled Gateway A as in the illustration.
Log in at the default address of
http://192.168.0.1
with the default user name of
admin
and
default password of
password
, or using whatever password and LAN address you have
chosen.
2. Configure the WAN (Internet) and LAN IP addresses of the FVS114.
a.
From the main menu Setup section, click the
Basic Setup
link to go back to the Basic
Settings menu.
FVS114
Gateway
B
Scenario 1
14.15.16.17
22.23.24.25
WAN IP
WAN IP
172.23.9.1/24
10.5.6.1/24
LAN IP
LAN IP
Gateway
A
FVS114
Summary of Contents for FVS114NA
Page 4: ...202 10098 01 April 2005 iv...
Page 12: ...202 10098 01 April 2005 xii Contents...
Page 211: ...Reference Manual for the ProSafe VPN Firewall FVS114 Glossary 11 202 10098 01 April 2005...
Page 212: ...Reference Manual for the ProSafe VPN Firewall FVS114 12 Glossary 202 10098 01 April 2005...