Define VPN client settings for Forcepoint NGFW

The Engine Editor contains settings for assigning valid IP addresses to VPN clients for connections through the VPN to the internal network.

If you use Stonesoft VPN Client, configure the Virtual Adapter. The alternative NAT Pool method does not allow the Stonesoft VPN Client computers to use your organization’s internal DNS servers. Virtual IP addresses work with all Stonesoft VPN Client versions and with third-party VPN clients that support this feature.

If you use Stonesoft VPN Client, the policy-based VPN configuration defined in the Management Client is also used for creating the configuration for Stonesoft VPN Client. Stonesoft VPN Client downloads the settings from the VPN gateway either manually or automatically whenever there are relevant changes. All IPsec and address management settings are included in the download. For example, the download includes information about which encryption methods are used and which internal networks clients can access through the gateway. The decision whether a VPN tunnel is used is based on the IP addresses you have defined for the Sites of the gateway.

For third-party VPN clients and external VPN gateways, you must duplicate the VPN Gateway settings in the configuration of the VPN client or gateway. You must also duplicate the VPN Gateway settings for engines under a different administrative Domain. The settings that you must duplicate include the following:
  • All IPsec-related settings, such as the authentication, encryption, and integrity checking options.
  • The encryption domain (the IP addresses that are allowed in the VPN as a source or destination IP address).

If a VPN Gateway that contains VPN Client settings is used in a route-based VPN, the VPN Client settings are ignored.

Note: The Virtual Adapter IP addresses must be assigned by a DHCP server. It is not possible to define the IP addresses in the VPN client or in the VPN gateway configuration. When you use a Single Firewall's internal DHCP server, use the IP address of the interface on which the internal DHCP server is enabled as the IP address of the DHCP Server element.

  For more details about the product and how to configure features, click Help or press F1.

Steps

  1. Right-click a Firewall element, then select Edit <element type>.
  2. Browse to VPN > VPN Client.
  3. Configure the settings.
    If you selected a VPN Mode that includes SSL VPN, configure the settings in the Virtual Address section.
  4. Click Save.

Engine Editor – VPN – VPN Client

Use this branch to change settings that are used when the engine acts as a VPN Gateway in a mobile VPN.

Option Definition
Gateway Display Name If you want to display a different name for the Gateway to Mobile VPN users, enter the name for the VPN Gateway element.
VPN Type Defines the type of tunnels the mobile VPN supports.
  • IPsec VPN — The mobile VPN only supports IPsec tunnels.
  • SSL VPN — The mobile VPN only supports SSL VPN tunnels.
  • Both IPsec & SSL VPN — The mobile VPN supports IPsec and SSL VPN tunnels.
SSL Port

(SSL VPN only)

The port for SSL VPN tunnels.
TLS Cryptography Suite Set

(SSL VPN only)

The cryptographic suite for SSL VPN tunnels. Click Select to select an element.
Note: Do not change the default setting unless you have a specific reason to do so.
Authentication Timeout

(SSL VPN only)

The timeout for Stonesoft VPN Client user authentication.
Option Definition
Local Security Checks section Defines whether the Stonesoft VPN Client checks for the presence of basic security software to stop connections from risky computers.
  • Anti-Virus is enabled — Requires anti-virus software to be enabled on the computers of mobile VPN users.
  • Firewall is enabled — Requires firewall software to be enabled on the computers of mobile VPN users.
  • Windows Update is enabled — Requires the Windows Update service to be enabled on the computers of mobile VPN users.
Option Definition
Virtual Address section Options for configuring the Stonesoft VPN Client with virtual IP addresses assigned by a DHCP server for connections inside the VPN.
DHCP Mode Specifies how DHCP requests from VPN clients are sent.
  • Disabled (IPsec VPN type only) — DHCP is not enabled.
  • Direct — When selected, the engine sends a normal DHCP client broadcast message to a DHCP server located in a directly connected network.
    Note: This option is intended for backward compatibility with Forcepoint NGFW versions earlier than version 5.9.
  • Relay — When selected, the engine sends unicast DHCP relay messages for VPN clients’ DHCP requests.
Note: If SSL VPN or Both IPsec & SSL VPN is selected from the VPN Type drop-down list, only the Direct and DHCP Relay are shown.
Interface

(Direct DHCP mode only)

The source address for the DHCP packets when querying the DHCP server (the interface toward the DHCP server).
Interface for DHCP Relay

(Relay DHCP mode only)

The source address for the DHCP packets when querying the DHCP server (the interface toward the DHCP server).
DHCP Server (NGFW < 5.9)

(Direct DHCP mode only)

The DHCP server that assigns IP addresses for the VPN clients.
Note: This option is intended for backward compatibility with Forcepoint NGFW versions earlier than version 5.9.
DHCP Servers

(Relay DHCP mode only)

The DHCP server that assigns IP addresses for the VPN clients. Click Add to add an element to the table, or Remove to remove the selected element.
Add Information (Optional) Specifies what VPN Client user information is added to the Remote ID option field in the DHCP Request packets.
  • Add User Information — When selected, VPN Client user information (in the form user@domain) is automatically added to the Remote ID option field in the DHCP Request packets.
  • Add Group Information — When selected, VPN Client user information (in the form group@domain) is automatically added to the Remote ID option field in the DHCP Request packets.
  • None — When selected, no user or user group information is added to the Remote ID option field in the DHCP Request packets.
Restrict Virtual Address Ranges When selected, the VPN gateway restricts the VPN clients’ addresses to the specified range, even if the DHCP server tries to assign some other IP address. Enter the IP address range in the field on the right.
Proxy ARP When selected, the engine acts as a proxy for the VPN clients’ ARP requests. Enter the IP address range for proxy ARP in the field on the right.
Option Definition
Secondary IPsec VPN Gateways section

(Optional)

(IPsec VPN type only)

Other IPsec VPN gateways to contact in case there is a disruption at the IPsec VPN gateway end (in the order of contact). Click Add to add a row to the table, or Remove to remove the selected row. Click Up or Down to move the selected element up or down.