18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 14: Configuring Virtual Private Networks<br />

Configuring VPN Security Associations<br />

5 In the Mode field, specify how the remote end is operating. The valid<br />

options are:<br />

• Fixed IP—Select this option if the IP address <strong>of</strong> the remote end is<br />

always the same. You must also provide the IP address <strong>of</strong> the remote<br />

end in the Remote IP field.<br />

• Dynamic IP Client—Select this option if the remote end is a device<br />

whose IP address is not fixed. Example: A salesperson that gains<br />

Internet access from a laptop.<br />

• Dynamic IP Restricted Client—Select this option if the remote end is a<br />

device whose IP address is not fixed. Example: A salesperson that<br />

gains Internet access from a laptop. The difference between this option<br />

and Dynamic IP Client is that the remote end is assigned a virtual IP<br />

address from a range specified by using either a Client Address Pool or<br />

a range <strong>of</strong> acceptable external IP addresses. You restrict the range <strong>of</strong> IP<br />

addresses available to the remote end by using either the Client<br />

Address Pool field or the Dynamic Virtual Address Range field.<br />

Important:You can only use Dynamic IP Client or Dynamic IP Restricted<br />

Client if automatic key management is used.<br />

6 [Conditional] Determine if you want remote clients to make connections<br />

using only the IP addresses contained within one <strong>of</strong> the available client<br />

address pools. If so, use the Client Address Pool drop-down list arrow to<br />

select the client address pool you want to use. With this option, the<br />

<strong>Sidewinder</strong> <strong>G2</strong> selects an IP address from the available pool and assigns it<br />

to the client. (This field is available only if you select Fixed IP or Dynamic IP<br />

Restricted Client in the Mode field.)<br />

Note: See “Configuring client address pools” on page 407 for information on<br />

creating a client address pool.<br />

7 In the Local IP field, indicate which IP address to use as the local gateway<br />

by selecting one <strong>of</strong> the following:<br />

• Use Localhost IP—Select this option to have the <strong>Sidewinder</strong> <strong>G2</strong> assign<br />

the IP address. The <strong>Sidewinder</strong> <strong>G2</strong> uses its routing table to<br />

automatically determine which interface or alias address is associated<br />

with a route to reach the remote gateway.<br />

• Specify IP—Select this option to configure a specific IP address. This IP<br />

address should be one <strong>of</strong> the <strong>Sidewinder</strong> <strong>G2</strong>’s interface or alias<br />

addresses, and that interface must have a route to reach the remote<br />

gateway.<br />

Note: If configuring a VPN for an HA cluster, be sure to use the localhost option<br />

or specify an alias shared by the cluster.<br />

8 To add or modify a local network address to the Local Network/IP list (a list<br />

<strong>of</strong> network names or IP addresses the <strong>Sidewinder</strong> <strong>G2</strong> can use in a VPN<br />

association), click New or Modify, respectively. See “Adding or modifying an<br />

IP address” for details.<br />

441

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!