WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide WatchGuard Firebox System 4.6 User Guide

watchguard.com
from watchguard.com More from this publisher
13.07.2015 Views

Configuring WatchGuard VPN• Watch for log entries as the Firebox reboots that show local and remote VPN IPaddresses.• Check the Firebox status once it has booted. There should be an entry for a VPNinterface directly following the entry for eth2.• Check the Control Center display for tunnel status.If none of these indicators is present, review all settings on both Fireboxes, doublecheckthat the passphrases are the same, and verify the remote IP addresses.132

CHAPTER 18Configuring the Fireboxfor Remote User VPNRemote user virtual private networking (RUVPN) establishes a secure connectionbetween an unsecured remote host and a protected network over an unsecurednetwork. RUVPN connects an employee on the road or working from home to trustedand optional networks behind a Firebox using a standard Internet dial-up connectionwithout compromising security.WatchGuard Firebox System offers two types of RUVPN:Remote User PPTPUses the Point-to-Point Tunneling Protocol. This type of RUVPN is included withthe basic WatchGuard package and supports up to 50 concurrent sessions perFirebox. Works with any Firebox encryption level.Mobile User VPNUses Internet Protocol Security. This type of RUVPN is an optional feature of theWatchGuard package. It requires strong or medium encryption.RUVPN requires configuration of both the Firebox and the end-user remote hostcomputers. This section describes how to configure a Firebox for both types ofRUVPN. For information on configuring the remote host, see “Preparing a Host forRemote User VPN” on page 141.Remote User PPTP and Mobile User VPN require that the ManagementStation be upgraded to either medium or strong encryption level. The mediumand strong encryption upgrade files are available to eligible users on theLiveSecurity Service Web site at http://www.watchguard.com/support.Configuration checklistBefore configuring a Firebox to use remote user virtual private networking (RUVPN),gather the following information:• The IP addresses to assign to the remote client during RUVPN sessions. The IPaddresses cannot be addresses currently in use in the network.User Guide 133

CHAPTER 18Configuring the <strong>Firebox</strong>for Remote <strong>User</strong> VPNRemote user virtual private networking (RUVPN) establishes a secure connectionbetween an unsecured remote host and a protected network over an unsecurednetwork. RUVPN connects an employee on the road or working from home to trustedand optional networks behind a <strong>Firebox</strong> using a standard Internet dial-up connectionwithout compromising security.<strong>WatchGuard</strong> <strong>Firebox</strong> <strong>System</strong> offers two types of RUVPN:Remote <strong>User</strong> PPTPUses the Point-to-Point Tunneling Protocol. This type of RUVPN is included withthe basic <strong>WatchGuard</strong> package and supports up to 50 concurrent sessions per<strong>Firebox</strong>. Works with any <strong>Firebox</strong> encryption level.Mobile <strong>User</strong> VPNUses Internet Protocol Security. This type of RUVPN is an optional feature of the<strong>WatchGuard</strong> package. It requires strong or medium encryption.RUVPN requires configuration of both the <strong>Firebox</strong> and the end-user remote hostcomputers. This section describes how to configure a <strong>Firebox</strong> for both types ofRUVPN. For information on configuring the remote host, see “Preparing a Host forRemote <strong>User</strong> VPN” on page 141.Remote <strong>User</strong> PPTP and Mobile <strong>User</strong> VPN require that the ManagementStation be upgraded to either medium or strong encryption level. The mediumand strong encryption upgrade files are available to eligible users on theLiveSecurity Service Web site at http://www.watchguard.com/support.Configuration checklistBefore configuring a <strong>Firebox</strong> to use remote user virtual private networking (RUVPN),gather the following information:• The IP addresses to assign to the remote client during RUVPN sessions. The IPaddresses cannot be addresses currently in use in the network.<strong>User</strong> <strong>Guide</strong> 133

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!