Define a VPN site
You must define Site elements for all NGFW Engines and External VPN Gateways that are used in policy-based VPNs. You must also define sites for NGFW Engines and External VPN Gateways that are used in route-based VPN tunnels in which the value of the Encryption option is Tunnel Mode.
The Site elements must always contain the actual IP addresses that are used inside the VPN tunnel. If traffic in the tunnel is subject to NAT, you must add the NAT addresses to the site. For NGFW Engines, you must add both the NAT addresses and any untranslated IP addresses that are not automatically added to the site. Sites for External VPN Gateways only require the translated address space that the NGFW Engine actually contacts.
The local and remote site definitions must match the same information about the other gateways involved in the VPN because the gateways verify this information during IKE negotiation. When creating VPNs with external Gateways, make sure that the IP address spaces of both gateways are defined identically in the SMC and on the external device. Otherwise, the VPN establishment can fail in one or both directions. Make sure to update the policies of any firewalls that are involved in the VPN when there are changes in the Site elements at either end.
If you want to use a central gateway as a hub that forwards traffic from one VPN tunnel to another, include all IP addresses that are accessible through the central gateway in the central gateway’s Site elements.
For more details about the product and how to configure features, click Help or press F1.
Steps
Next steps
VPN Site Properties dialog box
Use this dialog box to view or edit the properties a VPN site.
Option | Definition |
---|---|
General tab | |
Name | The name of the element. |
Comment | An optional comment for your own reference. |
Search | Opens a search field for the selected element list. |
Up (Backspace) | Returns to the previous folder. |
New | This option is not available in this dialog box. |
Tools |
|
VPN References tab | |
VPN | Shows the VPNs where this site is used. |
Enable | When selected, the site is enabled in the specified VPN. |
Mode | Defines the mode for the Site for each VPN in which it is enabled.
|