13.07.2015 Views

WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Branch office VPN with IPSecFrom Policy Manager:1 Select Network => Branch Office VPN => Basic DVCP.2 Select the tunnel policy. Click Edit.The DVCP Client Wizard opens and displays the tunnel properties.3 Use the Next and Back buttons to move through the DVCP Client Wizard andreconfigure tunnel properties. When complete, click Finish.4 Save the configuration file to the <strong>Firebox</strong>.The next time the client contacts the server, it will automatically note the tunnel policy changeand download the modifications. If the network address range on a client has changed, the clientautomatically restarts.Removing a tunnel to a deviceWhen a tunnel is removed, the DVCP client can no longer communicate with theserver. The next time the DVCP client tries to contact the server, contact will bedenied. If these settings were never manually configured, the client will use192.168.111.0/24 as the DHCP network range.From Policy Manager:1 Select Network => Branch Office VPN => Basic DVCP.2 Select the tunnel policy. Click Remove.The policy is removed from the DVCP Configuration dialog box.Defining a <strong>Firebox</strong> as an Enhanced DVCP ClientIf a <strong>Firebox</strong> is part of a DVCP VPN setup, enable it as a client and configure itssettings.From Policy Manager:1 Select Network => Enhanced DVCP Client.2 Enable the Enable this <strong>Firebox</strong> as a DVCP Client checkbox.3 In the <strong>Firebox</strong> Name field, specify the name of the <strong>Firebox</strong>.4 To log messages for the DVCP client, enable the Enable debug log messages forthe DVCP Client checkbox.5 To add DVCP servers that the client can communicate with, click Add.6 Enter the IP address. Enter the scared secret. Click OK.Branch office VPN with IPSecIPSec is a protocol that encrypts and/or authenticates traffic at the IP level betweenany mix of arbitrary hosts and security gateways. For more information about IPSecand how <strong>WatchGuard</strong> implements branch office VPN with IPSec, see the NetworkSecurity Handbook.• Determine the tunnel and policy endpoints• Select an encryption method• Select an authentication method124

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!