User Guide
121
CHAPTER 17
Configuring Branch Office Virtual
Private Networking
Branch office virtual private networking (VPN) creates a secure tunnel, over an
unsecure network, between two networks protected by the WatchGuard Firebox
System or between a WatchGuard Firebox and an IPSec-compliant device. Using
branch office VPN, you can connect two or more locations over the Internet while still
protecting the resources of your trusted and optional networks.
WatchGuard offers three branch office VPN methods:
• DVCP VPN
This method defines a Firebox as a DVCP server at the center of a distributed
array of WatchGuard Firebox and SOHO clients.
• IPSec (Internet Protocol Security)
This method uses IPSec to tunnel between a WatchGuard Firebox and an IPSec-
compliant device from another vendor or between two Fireboxes.
• WatchGuard VPN
This method uses the WatchGuard proprietary secure connection, called
WatchGuard VPN, to create a tunnel between two WatchGuard Fireboxes.
Configuration checklist
Before implementing branch office VPN, gather the following information:
• IP address of both ends of the tunnel.
A given pair of Fireboxes can establish only one VPN connection between
them. However, a single Firebox can tunnel to multiple branch locations.
Incoming connections from branch office VPN networks can access machines
on the Trusted interface regardless of whether the local machines are using
NAT.
Connections made through a branch office VPN are exempt from Simple
NAT.
Addresses used for VPN must not be on the Blocked Sites list.
Summary of Contents for Firebox FireboxTM System 4.6
Page 1: ...WatchGuard Firebox System User Guide Firebox System 4 6 ...
Page 16: ...6 ...
Page 20: ...LiveSecurity broadcasts 10 ...
Page 44: ...LiveSecurity Event Processor 34 ...
Page 52: ...Defining a Firebox as a DHCP server 42 ...
Page 68: ...Service precedence 58 ...
Page 78: ...Configuring a service for incoming static NAT 68 ...
Page 92: ...Establishing an OOB connection 82 ...
Page 94: ...84 ...
Page 112: ...HostWatch 102 ...
Page 118: ...Working with log files 108 ...
Page 130: ...120 ...
Page 158: ...Configuring debugging options 148 ...