OfficeConnect VPN Firewall User’s Manual Chapter 14. Configuring IPSec VPN
89
1. Log into Configuration Manager as admin, click the VPN menu, and
then click the IPSec submenu.
2. Click on the check box in front of rule to be deleted.
3. Click on the button to delete selected rules.
14.3.4 Display VPN Rules
To see existing VPN rules, follow the instructions below:
1. Log into Configuration Manager as admin, click the VPN menu, and
then click the IPSec submenu.
2. All the configured VPN policies are displayed in the VPN policy list
table.
14.4 VPN Connection Examples
Gateways with integrated VPN and Firewall are useful in scenarios where:
The traffic between branch offices is protected by VPN and
Traffic destined for public Internet goes through Firewall/NAT.
To avoid NAT/IPSec interoperability issues, outgoing traffic is first processed by
Firewall/NAT and then by IPSec. Hence, you must ensure that appropriate
Firewall rules are configured to let the VPN traffic goes through. This section
describes these scenarios and presents step-by-step instructions for configuring
these scenarios.
14.4.1 Intranet Scenario – firewall + VPN and no NAT for VPN
traffic
This is a common scenario where traffic to the public Internet goes through the
Firewall/NAT only and traffic between private networks is allowed without NAT
before IPSec processing. The same authority administers the networks that are
protected by VPN to avoid any possible address clash. Configure each of the
OfficeConnect Gigabit VPN Firewall for the Intranet scenario using the following
steps:
Configure VPN connection rules.
Configure Firewall access rules to allow inbound and outbound VPN traffic.
Configure a Firewall self rule to allow IKE packets into the OfficeConnect
Gigabit VPN Firewall.
14.4.1.1 Configure Rules on OfficeConnect Gigabit VPN Firewall
1 (ISR1)
This section describes the steps to establish the VPN/Firewall for the Internet
scenario. Figure 14.4 depicts the typical Intranet connections. Note that ADSL or
cable modem is not required if the two networks are connected via Ethernet
connections.The setting of each configuration step is illustrated in a figure. For
instructions on configuration of each step, please refer to the corresponding
section for details.
Commentaires sur ces manuels