Internet. SonicWALL IP 10.100.30.1 SEV 7.0.4 IP 10.100.50.8 IP 172.18.0.1 IP 192.168.170.1. Network 192.168.170.0 Mask 255.255.255.



Similar documents
Keying Mode: Main Mode with No PFS (perfect forward secrecy) SA Authentication Method: Pre-Shared key Keying Group: DH (Diffie Hellman) Group 1

Configuration Guide. How to set up the IPSec site-to-site Tunnel between the D-Link DSR Router and the Sonicwall Firewall.

IPsec VPN Application Guide REV:

Configure an IPSec Tunnel between a Firebox Vclass & a Check Point FireWall-1

RouteFinder. IPSec VPN Client. Setup Examples. Reference Guide. Internet Security Appliance

Configuration Guide. How to set up the IPSec site-to-site Tunnel between the D-Link DSR Router and the Fortinet Firewall. Overview

How To Establish IPSec VPN connection between Cyberoam and Mikrotik router

Configuration Guide. How to set up the IPSec site-to-site Tunnel between the D-Link DSR Router and the Cisco Firewall. Overview

Configuring a Check Point FireWall-1 to SOHO IPSec Tunnel

Katana Client to Linksys VPN Gateway

Configuring TheGreenBow VPN Client with a TP-LINK VPN Router

UTM - VPN: Configuring a Site to Site VPN Policy using Main Mode (Static IP address on both sites) i...

VPN Configuration of ProSafe Client and Netgear ProSafe Router:

Create a VPN on your ipad, iphone or ipod Touch and SonicWALL NSA UTM firewall - Part 1: SonicWALL NSA Appliance

How To Industrial Networking

Creating a Gateway to Client VPN between Sidewinder G2 and a Mac OS X Client

Network/VPN Overlap How-To with SonicOS 2.0 Enhanced Updated 9/26/03 SonicWALL,Inc.

Application Notes. How to Configure UTM with Apple OSX and ios Devices for IPsec VPN

DFL-210/260, DFL-800/860, DFL-1600/2500 How to setup IPSec VPN connection

How To Establish IPSec VPN between Cyberoam and Microsoft Azure

Fireware How To VPN. Introduction. Is there anything I need to know before I start? Configuring a BOVPN Gateway

IP Office Technical Tip

Windows XP VPN Client Example

ISG50 Application Note Version 1.0 June, 2011

Chapter 5 Virtual Private Networking Using IPsec

How To Set Up A Vpn Tunnel Between Winxp And Zwall On A Pc 2 And Winxp On A Windows Xp 2 On A Microsoft Gbk2 (Windows) On A Macbook 2 (Windows 2) On An Ip

IPSec Pass through via Gateway to Gateway VPN Connection

Netgear ProSafe VPN firewall (FVS318 or FVM318) to Cisco PIX firewall

Configuring IPsec between a Microsoft Windows XP Professional (1 NIC) and the VPN router

Configuring IPsec VPN with a FortiGate and a Cisco ASA

Lab 4.4.8a Configure a Cisco GRE over IPSec Tunnel using SDM

Configuring a Site-to-Site VPN Tunnel Between Cisco RV320 Gigabit Dual WAN VPN Router and Cisco (1900/2900/3900) Series Integrated Services Router

Configuring an IPSec Tunnel between a Firebox & a Check Point FireWall-1

Deploying the Barracuda Link Balancer with Cisco ASA VPN Tunnels

VPN Consortium Scenario 1: Gateway-to-Gateway with Preshared Secrets

Setting up VPN Tracker with Nortel VPN Routers

Configuration Guide. How to establish IPsec VPN Tunnel between D-Link DSR Router and iphone ios. Overview

How to configure VPN function on TP-LINK Routers

VPN Consortium Scenario 1: Gateway-to-Gateway with Preshared Secrets

Use Shrew Soft VPN Client to connect with IPSec VPN Server on RV130 and RV130W

DI-804HV with Windows 2000/XP IPsec VPN Client Configuration Guide

ZyWALL 5. Internet Security Appliance. Quick Start Guide Version 3.62 (XD.0) May 2004

How to configure VPN function on TP-LINK Routers

Technical Document. Creating a VPN. GTA Firewall to WatchGuard Firebox SOHO 6 TD: GB-WGSOHO6

Configure VPN between ProSafe VPN Client Software and FVG318

Chapter 4 Virtual Private Networking

7. Configuring IPSec VPNs

Gateway to Gateway VPN Connection

How To Establish Site-to-Site VPN Connection. using Preshared Key. Applicable Version: onwards. Overview. Scenario. Site A Configuration

Chapter 8 Virtual Private Networking

CREATING AN IKE IPSEC TUNNEL BETWEEN AN INTERNET SECURITY ROUTER AND A WINDOWS 2000/XP PC

TechNote. Configuring SonicOS for Amazon VPC

VPN. VPN For BIPAC 741/743GE

How to access peers with different VPN through IPSec. Tunnel

OvisLink 8000VPN VPN Guide WL/IP-8000VPN. Version 0.6

VPNC Interoperability Profile

Establishing a VPN tunnel to CNet CWR-854 VPN router using WinXP IPSec client

VPN Wizard Default Settings and General Information

Configuring IPSec VPN Tunnel between NetScreen Remote Client and RN300

Using IPsec VPN to provide communication between offices

Chapter 6 Basic Virtual Private Networking

Netopia TheGreenBow IPSec VPN Client. Configuration Guide.

Configuring an IPsec VPN to provide ios devices with secure, remote access to the network

Global VPN Client Getting Started Guide

SonicWALL Check Point Firewall-1 VPN Interoperability

Configure IPSec VPN Tunnels With the Wizard

Vodafone MachineLink 3G. IPSec VPN Configuration Guide

Ingate Firewall. TheGreenBow IPSec VPN Client Configuration Guide.

Cyberoam Configuration Guide for VPNC Interoperability Testing using DES Encryption Algorithm

How To Configure L2TP VPN Connection for MAC OS X client

GNAT Box VPN and VPN Client

Virtual Private Network and Remote Access Setup

Configuring Internet Authentication Service on Microsoft Windows 2003 Server

ZyWALL USG-Series. How to setup a Site-to-site VPN connection between two ZyWALL USG series.

Configuring Windows 2000/XP IPsec for Site-to-Site VPN

STONEGATE IPSEC VPN 5.1 VPN CONSORTIUM INTEROPERABILITY PROFILE

Based on the VoIP Example 1(Basic Configuration and Registration), we will introduce how to dial the VoIP call through an encrypted VPN tunnel.

VNS3 to Cisco ASA Instructions. ASDM 9.2 IPsec Configuration Guide

Cisco RV 120W Wireless-N VPN Firewall

VPN Tracker for Mac OS X

SonicWALL Global Management System Configuration Guide Standard Edition

VPN L2TP Application. Installation Guide

Introduction to Security and PIX Firewall

IP Office Technical Tip

OfficeConnect Internet Firewall VPN Upgrade User Guide

Using IKEv2 on Juniper Networks Junos Pulse Secure Access Appliance

VPN Configuration Guide. ZyWALL USG Series / ZyWALL 1050

Configuring a VPN for Dynamic IP Address Connections

VPNs. Palo Alto Networks. PAN-OS Administrator s Guide Version 6.0. Copyright Palo Alto Networks

Chapter 6 Virtual Private Networking

The BANDIT Products in Virtual Private Networks

Application Note: Integrate Juniper IPSec VPN with Gemalto SA Server. October

Cisco QuickVPN Installation Tips for Windows Operating Systems

How To Configure An Ipsec Tunnel On A Network With A Network Gateways (Dfl-800) On A Pnet 2.5V2.5 (Dlf-600) On An Ipse Vpn

IP Office Technical Tip

VPN Configuration of ProSafe VPN Lite software and NETGEAR ProSafe Router:

Setting up D-Link VPN Client to VPN Routers

VPN Tracker for Mac OS X

GB-OS. VPN Gateway. Option Guide for GB-OS 4.0. & GTA Mobile VPN Client Version 4.01 VPNOG

Administrator's Guide

Transcription:

Prepared by SonicWALL, Inc. 6/10/2003 Introduction: VPN standards are still evolving and interoperability between products is a continued effort. SonicWALL has made progress in this area and is interoperable with Symantec Enterprise VPN(SEV) using IKE as shown below. Advanced setups are possible but are not covered in this document. This tech-note assumes the reader has a working knowledge of SEV management tools and SonicWALL appliance configuration. This tech-note describes the required steps to set-up a compatible Security Association on both SEV and SonicWALL products. Technical Notes: SonicWALL has tested VPN interoperability with SEV 7.0.4 and SonicWALL Pro 300 version 6.4.2.0 using the following VPN Security Association information: Keying Mode: IKE IKE Mode: Main Mode with No PFS (perfect forward secrecy) SA Authentication Method: Pre-Shared key Keying Group: DH (Diffie Hellman) Group 2 Encryption and Data Integrity: ESP 3DES with SHA1 EXAMPLE: The network configuration shown below is used in the example VPN configuration. The example will configure a VPN using 3DES encryption with SHA1 and without PFS. SEV 7.0.4 IP 10.100.50.8 Internet SonicWALL IP 10.100.30.1 IP 192.168.170.1 IP 172.18.0.1 Network 192.168.170.0 Mask 255.255.255.0 Network 172.18.0.0 Mask 255.255.0.0 Page 1 of 18

SonicWALL Configuration On the SonicWALL, create an SA Change the IPSec Keying Mode to IKE using pre-shared secret Name your SA (In this example, Raptor) Fill in the IPSec gateway (in this example, 10.100.50.8) Select Main Mode for Exchange Select Group 2 for Phase 1 DH Group Select 3DES SHA1 for Phase 1 Encryption/Authentication Select ESP 3DES HMAC SHA1 for Phase 2 Encryption/Authentication Enter your Shared Secret, (In this example, passwordpasswordpass) Fill in the appropriate Destination Network (in this example, 192.168.170.0) and Subnet Mask (in this example, 255.255.255.0) A Sample Screen shot from SonicWALL firmware version 6.4.2.0 is displayed below Page 2 of 18

SEV 7.0.4 Configuration Create SEV Gateway Open up base components Right click on Network Entities, select New, and select Security Gateway Name the gateway (in this example, Raptor) Make sure Type is Security Gateway Page 3 of 18

Select the Security Gateway Tab Select the WAN IP address of the raptor firewall from the IP Address pull down menu (10.100.50.8) Check Enable IKE Make sure Phase 1 ID is left blank Click OK Page 4 of 18

Create SonicWALL Gateway Right click on Network Entities, select New, and select Security Gateway Name the gateway (in this example, SonicWALL) Make sure Type is Security Gateway Page 5 of 18

Select the Security Gateway Tab Enter the WAN IP address of the SonicWALL (10.100.30.1) Check Enable IKE Make sure Phase 1 ID is left blank Select Shared Secret Enter the same secret you entered on the SonicWALL (passwordpasswordpass) Note: Raptor requires this to be at least 20 characters long Click OK Page 6 of 18

Create SEV Subnet Right click on Network Entities, select New, and select Subnet Enter a Name for the Subnet (Raptor_LAN) Make sure Type is Subnet Page 7 of 18

Click on the Address Tab Enter the LAN network(192.168.170.0) and subnet mask(255.255.255.0) which is behind the SEV Click OK Page 8 of 18

Create SonicWALL Subnet Right click on Network Entities, select New, and select Subnet Enter a Name for the Subnet (SonicWALL_LAN) Make sure Type is Subnet Page 9 of 18

Click on the Address Tab Enter the LAN network(172.18.0.0) and subnet mask(255.255.0.0) which is behind the SonicWALL Click OK Page 10 of 18

Edit IKE Policy Open up the Virtual Private networks folder Select IKE Policy Right click global_ike_policy, select properties Select SHA1 for Data Integrity Preference 1 st Select BLANK for Data Integrity Preference 2 nd Select 3DES for Data Privacy Preference 1 st Select BLANK for Data Privacy Preference 2 nd Select Group2 for Diffie-Hellman Preference 1st Select BLANK for Diffie-Hellman Preference 2 nd Enter 28800 seconds for Time Expiration Click OK NOTE: This is for Phase One and should match the SonicWALL Phase One Settings. See page 2 Page 11 of 18

Create VPN Policy Under Virtual Private Networks Right Click on VPN Policy, select New, Select VPN Policy Name the policy (IPSec Policy) Select IPSEC/IKE for encapsulation protocol Page 12 of 18

Select the IPSEC/IKE Tab Select SHA1 for Data Integrity Preference 1 st Leave Blank for Data Integrity Preference 2 nd Select 3DES for Data Privacy Preference 1 st Leave Blank for Data Privacy Preference 2 nd Leave NONE for Data Compression NOTE: This is for Phase Two and should match the SonicWALL Phase Two Settings. See page 2 Page 13 of 18

Select the Timeouts Tab Set Lifetime Timeout (480 minutes) Page 14 of 18

Select Options Tab Select <NONE> for filters(this is not necessary, but if you have problems bringing up the tunnel make sure <NONE> is selected so filters can be eliminated as the problem) Page 15 of 18

Select the Advanced Tab Select Tunnel Mode Make sure PFS is not checked. Click OK NOTE: This is for Phase Two and should match the SonicWALL Phase Two Settings. See page 3 Page 16 of 18

Create Secure Tunnel Right Click Secure Tunnels, select New, and select Secure Tunnel Name the Secure Tunnel (SonicWALL-Raptor) Select Raptor_LAN for Local Entity Select SonicWALL_LAN for Remote Entity Select Raptor for Local Gateway Select SonicWALL for Remote Gateway Select IPSec Policy for VPN Policy Click OK Click SAVE on the SEV console Page 17 of 18

Trouble Shooting Tips: Stop and Start the SEV firewall if you can t get the tunnel up Make sure that you have not defined a phase1 ID for the SEV or SonicWALL security gateways. See page 5 and page 7. Verify that your global_ike_policy settings on SEV match the Phase one settings on SonicWALL Verify that your VPN Policy settings on SEV match the Phase two settings on SonicWALL Page 18 of 18