Edit a policy-based VPN
The policy-based VPN element can be configured in two ways: the basic properties are defined in the Policy-Based VPN element’s properties. All other settings, including the included gateways, Sites, and tunnels are configured in the Policy-Based VPN editing view.
For more details about the product and how to configure features, click Help or press F1.
Steps
- Select Configuration, then browse to SD-WAN.
- Browse to Policy-Based VPNs.
-
Open the correct view for the settings that you want to edit:
- To edit the basic properties, right-click the Policy-Based VPN element, then select Properties.
- To adjust the other settings, right-click the Policy-Based VPN element, then select Edit <element name>.
Policy-Based VPN editing view
Use this view to create and modify policy-based virtual private networks (VPN).
Option | Definition |
---|---|
Resources | Use this pane to create and add elements to a VPN. |
Search | Opens a search field for the selected element list. |
Up (Backspace) | Returns to the previous folder. |
New | Opens the associated dialog box to create an element. |
Tools |
|
Option | Definition |
---|---|
Policy toolbar | |
Save | Saves the changes. |
Tools menu | |
Properties | Opens the VPN Properties dialog box. |
Sign VPN Client Certificate | Opens the Sign VPN Client Certificate dialog box. |
Filter by Gateway | Shows only tunnels where the selected gateway is used. Only available on the Tunnels tab. |
Filter by Firewall | Shows only tunnels where the selected firewall is used. Only available on the Tunnels tab. |
No Filtering | Disables filtering. |
Option | Definition |
---|---|
Site-to-Site VPN tab | |
Tools |
|
Option | Definition |
---|---|
Mobile VPN tab | |
Select engines that provide Mobile VPN Access | Specifies the gateways that can be selected for mobile VPN access.
|
Option | Definition |
---|---|
Tunnels tab | |
Gateway A or Gateway B | VPN Gateway elements are used for
Gateway A; for
Gateway B, they can be VPN Gateway or External VPN Gateway elements.
Right-clicking on this type of cell opens these menu items:
|
VPN Profile |
Right-clicking on this type of cell opens these menu items:
|
Key | Verifies if the required pre-shared key is properly set. If you use pre-shared keys for authentication with external gateways, either set the key agreed with your partner or export the keys that have been automatically generated for your partner to use.
To view, change, or export the pre-shared key, double-click the Key cell. Right-clicking on this type of cell opens these menu items:
|
Validity | Verifies if the tunnel is valid. If a tunnel has a warning icon in the
Validity cell, right-click the tunnel and select
View issues. You must resolve all problems indicated in the messages shown.
Right-clicking on this type of cell opens these menu items:
|
Forwarding Gateways | Right-clicking on this type of cell opens these menu items:
|
Endpoint A or Endpoint B |
Select the endpoint IP addresses. You cannot use the same endpoint in a route-based VPN tunnel and a policy-based VPN tunnel. If loopback IP addresses are defined for a VPN Gateway, you can select a loopback IP address as the endpoint IP address. Right-clicking this type of cell opens these menu items:
|
IPsec Profile | Right-clicking on this type of cell opens these menu items:
|
Mode | Select the encapsulation mode for the tunnel. You can select the encapsulation mode individually for each tunnel.
Right-clicking on this type of cell opens these menu items:
|
Validity | Verifies if the tunnel is valid.
Right-clicking on this type of cell opens these menu items:
|
Option | Definition |
---|---|
Panes in the Policy-Based VPN editing view | |
Info pane | Shows information about the selected element. |
Issues pane | Shows issues in the VPN configuration, such as incompatible settings. |
Link Summary pane | Shows a summary of the policy-based VPN configuration. |