Virtual Private Networking Using IPSec Connections
143
ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308
3. Click Apply to save your settings. The IPSec VPN policy is now added to the List of VPN
Policies table on the VPN Policies screen. By default, the VPN policy is enabled.
Table 30. IPSec VPN Wizard settings for a client-to-gateway tunnel
Setting Description
About VPN Wizard
This VPN tunnel will connect to
the following peers:
Select the VPN Client radio button. The default remote FQDN
(srx_remote.com) and the default local FQDN (srx_local.com) display in
the End Point Information section of the screen.
Connection Name and Remote IP Type
What is the new Connection
Name?
Enter a descriptive name for the connection. This name is used to help
you to manage the VPN settings; the name is not supplied to the remote
VPN endpoint.
What is the pre-shared key? Enter a pre-shared key. The key needs to be entered both here and on
the remote VPN gateway, or the remote VPN client. This key needs to
have a minimum length of 8 characters and should not exceed
49 characters.
This VPN tunnel will use
following local WAN Interface:
From the drop-down list, select one of the four WAN interfaces of the
VPN firewall to specify which WAN interface the VPN tunnel uses as the
local endpoint.
Enable RollOver If you have configured the VPN firewall to function in WAN auto-rollover
mode (see Configure the Auto-Rollover Mode and Failure Detection
Method on page 34), select the Enable RollOver check box. Then, from
the corresponding drop-down list, select the backup WAN interface. After
an auto-rollover has occurred, the VPN tunnel will be reestablished using
the backup WAN interface.
End Point Information
a
a. Both local and remote endpoints should be defined as either FQDNs or IP addresses. A combination of
an IP address and an FQDN is not supported.
What is the Remote Identifier
Information?
When you select the Client radio button in the About VPN Wizard section
of the screen, the default remote FQDN (srx_remote.com) is
automatically entered. Use the default remote FQDN, or enter another
FQDN.
What is the Local Identifier
Information?
When you select the Client radio button in the About VPN Wizard section
of the screen, the default local FQDN (srx_local.com) is automatically
entered. Use the default local FQDN, or enter another FQDN.
Secure Connection Remote Accessibility
What is the remote LAN IP
Address?
These fields are masked out for VPN client connections.
What is the remote LAN Subnet
Mask?