13.07.2015 Views

WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Using DVCP to connect to devicesNote also that if you configure a SOHO for both Basic and Enhanced DVCP, thegateway names must be different.From Policy Manager:1 Select Network => Branch Office VPN => Basic DVCP.The DVCP Configuration dialog box appears.2 Click Add.3 Enter a distinctive name for the DVCP client. Enter the shared key. Click Next.The client name appears in the DVCP Configuration dialog box as well as the Control Center<strong>Firebox</strong> and Tunnel Status display.4 Enter the address range which the DVCP client will be able to access.5 Select a client type:Telecommuter IP AddressThe SOHO is assigned a single IP address. This is the device’s virtual IP addresson the Trusted network of the <strong>Firebox</strong> to which the device will be allowed access.SOHO Private NetworkThe SOHO is assigned an entire network.6 Click Next.7 Use the Type drop list to select an encryption type.Options include: ESP (Encapsulated Security Payload) or Authentication Only.8 Use the Authentication drop list to select an authentication method.Options include: None (no authentication), MD5-HMAC (128-bit algorithm), and SHA1-HMAC(160-bit algorithm).9 Use the Encryption drop list to select an encryption method.Options include: None (no encryption), DES-CBC (56-bit encryption), and 3DES-CBC (168-bitencryption).10 Enter values to set the interval to force key expiration. Enter traffic in kilobytesand/or time in hours.The default values are 8192 kilobytes or 24 hours.11 Click Next. Click Finish.The new policy appears in the DVCP Configuration dialog box. The <strong>WatchGuard</strong> device can nowbe connected, powered on, and configured. As part of the configuration process, it willautomatically download the appropriate tunnel information. You must provide the DVCP clientadministrator with the Client Name, shared key, and the server external interface IP address.Editing a tunnel to a deviceIt is possible to change the properties of a DVCP tunnel without adversely impactingthe DVCP client. Properties of a tunnel that you can modify without forcing the clientto reboot include:• Identification name• Shared key• Encryption/authentication level• TimeoutsYou can also change the network range of a <strong>WatchGuard</strong> client. However, when yousave the configuration to the server, it automatically triggers the client to reboot andload the new policy.<strong>User</strong> <strong>Guide</strong> 123

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!