
Configuring the IRE VPN Client for use with the Firewall 137
9 Select the Manual IPSec and the Logging radio buttons.
10 Press the Edit button. Select the SPI Key for this VPN Tunnel.
11 Press the OK button when finished with the IPSec properties and press
the OK button when finished with the Encryption properties.
12 From the Policy menu, select Install to activate the security policy. The VPN
tunnel will function once the remote Firewall has been configured with a
corresponding security association.
Configuring the
Firewall
1 Go to the VPN Configure screen in the Firewall Web interface. Create a
Firewall Security Association, using manual key encryption, and name it
Check Point (any name will work). Do not use the Allow Remote Clients
checkbox.
2 Enter a valid destination address range (referring to the LAN behind
Check Point). Specify the Check Point's external address as the IPSec
Gateway address.
3 Select the Encryption Method Encrypt for Checkpoint (ESP DES rfc1829).
Make sure the Encryption Key and the SPIs match the values specified in
the Check Point screens (The Firewall doesn't need the '0x' prefixes to
denote hexadecimal fields like the Check Point does). There is no need for
an authentication key.
4 Update the screen and restart Firewall to activate the VPN configuration.
Configuring the IRE
VPN Client for use
with the Firewall
This section covers the configuration of the Firewall VPN capability and
the installation of the IRE VPN Client Software. There are several parts to
this process:
■
Setting up the GroupVPN Security Association
■
Installing the IRE VPN Client Software
■
Configuring the IRE VPN Client
DUA1611-0AAA02.book Page 137 Thursday, August 2, 2001 4:01 PM
Comentários a estes Manuais