13.07.2015 Views

WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Using DVCP to connect to devices• IP network addresses for the networks communicating with one another.• A common passphrase, known as a shared secret.• For <strong>WatchGuard</strong> VPN only, the local VPN IP address of each <strong>Firebox</strong>. It must beselected from a reserved network address that is not in use on either of thenetworks being connected. For more information, see RFC 1918 or “Setting UpNetwork Address Translation” on page 63.Both ends of the tunnel must use the same encryption method.Using DVCP to connect to devicesDynamic VPN Configuration Protocol (DVCP) is the <strong>WatchGuard</strong>-proprietaryprotocol that easily creates a virtual private network. The DVCP server is a <strong>Firebox</strong>that sits at the center of a distributed array of <strong>WatchGuard</strong> <strong>Firebox</strong>, SOHO, andSOHO|tc clients.How does DVCP work?The DVCP option causes the <strong>Firebox</strong> to act as a server. SOHOs can be DVCP clients,and <strong>Firebox</strong>es can either be DVCP clients or servers. The DVCP server maintains theconnections between two devices by storing all policy information–includingnetwork address range and tunnel properties such as encryption, timeouts, andauthentication. DVCP clients can retrieve this information from the server. The onlyinformation clients need to maintain is an identification name, shared key, and the IPaddress of the server External interface.You use the the DVCP Client Wizard to configure a device as a DVCP server and thencreate tunnels to each client <strong>Firebox</strong> or SOHO. The clients then contact the server andautomatically download the information needed for them to connect securely.Basic and Enhanced DVCP<strong>WatchGuard</strong> offers two types of DVCP:Basic DVCP simplifies establishing VPN tunnels between SOHO units and<strong>Firebox</strong>es. It cannot manage tunnels between two <strong>Firebox</strong>es.Enhanced DVCP manages tunnels between any two <strong>WatchGuard</strong> devices: SOHO to<strong>Firebox</strong>, <strong>Firebox</strong> to <strong>Firebox</strong>, and so on. Enhanced DVCP is available only if the VPNManager 2.0 option is installed.Creating a tunnel to a SOHO or SOHO|tcThe tunnels you create for SOHO clients must be completely distinct from any tunnelcreated for branch office VPN. In other words, no addresses in the DVCP client policyshould be in the same address range as any branch office policy.122

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!