CheckthisboxandselectaWANtoconnecttothisVPNautomaticallywhenthespecified
WANisdisconnected.Toactivatethisfunction,clickthe buttonnexttothe“Active”
option.
EnterthelocalLANsubnetshere.Ifyouhavedefinedstaticroutes,theywillbeshown
here.
UsingNAT,youcanmapaspecificlocalnetwork/IPaddresstoanother,andthepackets
receivedbyremotegatewaywillappeartobecomingfromthemappednetwork/IP
address.ThisallowyoutoestablishIPsecconnectiontoaremotesitethathasoneor
moresubnetsoverlappedwithlocalsite.
TwotypesofNATpoliciescanbedefined:
OnetoOneNATpolicy:ifthedefinedsubnetinLocalNetworkandNATNetworkhas
thesamesize,forexample,policy"192.168.50.0/24>172.16.1.0/24"willtranslatethe
localIPaddress192.168.50.10to172.16.1.10and192.168.50.20to172.16.1.20.Thisis
abidirectionalmappingwhichmeansclientsinremotesitecaninitiateconnectiontothe
localclientsusingthemappedaddresstoo.
ManytoOneNATpolicy:ifthedefinedNATNetworkontherighthandsideisanIP
address(orhavinganetworkprefix/32),forexample,policy"192.168.1.0/24>
172.168.50.1/32"willtranslateallclientsin192.168.1.0/24networkto172.168.50.1.This
isaunidirectionalmappingwhichmeansclientsinremotesitewillnotbeabletoinitiatea
connectiontothelocalclients.
ToaccessyourVPN,clientswillneedtoauthenticatebyyourchoiceofmethods.Choose
betweenthePresharedKeyandX.509Certificatemethodsofauthentication.