13.07.2015 Views

WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Configuring <strong>WatchGuard</strong> VPNConfiguring <strong>WatchGuard</strong> VPNUse <strong>WatchGuard</strong> VPN to implement branch office VPN between two <strong>Firebox</strong>es.<strong>WatchGuard</strong> VPN uses udp port 4104.<strong>WatchGuard</strong> VPN offers 40-bit encryption. <strong>WatchGuard</strong> VPN with 128-bitencryption can be used when both ends of the tunnel are licensed for enhancedencryption. Other encryption standards are available (128-bit DES and 3-DES).<strong>WatchGuard</strong> VPN configuration modelsThere are two models for configuring <strong>WatchGuard</strong> VPN:Two-box configurationConnect two networks over the Internet using two <strong>Firebox</strong>es.Multiple box configurationConnect one central <strong>Firebox</strong> to multiple remote networks over the Internet.- Add multiple VPN configurations to the central <strong>Firebox</strong>, and configure remote<strong>Firebox</strong>es accordingly.- Make sure that passphrases are unique to a single VPN connection.- On the central <strong>Firebox</strong>, use the same IP address for multiple remote <strong>Firebox</strong>es.However, the address can not be used for another purpose on either the centralor remote networks.Setting up <strong>WatchGuard</strong> VPNFrom Policy Manager:1 Select Network => Branch Office VPN => <strong>WatchGuard</strong> VPN.2 To set up a branch office, click Add.3 In the Remote <strong>Firebox</strong> IP field, enter the IP address of the External interface of theremote <strong>Firebox</strong>.4 In the Local <strong>Firebox</strong> IP field, enter an IP address from a reserved network not inuse on the local or remote networks.More information on reserved networks can be found in RFC 1918. You canuse the same local VPN IP address for multiple VPN connections whenspecifying more than one—for example, when there are several branch officesconnecting to a central office.5 In the text box to the left of the Add button, enter the IP address in slash notationof any remote network to which access should be granted from the local <strong>Firebox</strong> .Click Add.The remote <strong>Firebox</strong> must reciprocate by adding the local networks in its Remote Networks box.Because <strong>WatchGuard</strong> VPN is a peer-to-peer situation, each <strong>Firebox</strong> must have the other’snetwork listed.6 Click the Encryption tab.7 Under Encryption, select the number of bits used to encrypt the tunnel.The greater the number of bits, the stronger the encryption.130

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!