Connections

On the IPsec > Connections tab you can create and edit IPsecClosed connections.

To create an IPsec connection, proceed as follows:

  1. On the Connections tab, click New IPsec Remote Access Rule.

    The Add IPsec Remote Access Rule dialog box opens.

  2. Make the following settings:

    Name: Enter a descriptive name for this connection.

    Interface: Select the name of the interface which is used as the local endpoint of the IPsec tunnel.

    Local networks: Select or add the local networks that should be reachable through the VPN tunnel. How to add a definition is explained on the Definitions & Users > Network Definitions > Network Definitions page.

    Virtual IP pool: The IP address pool where clients get an IP address assigned from in case they do not have a static IP address. The default pool is VPN Pool (IPsec) which comprises the private IP space 10.242.4.0/24. You can, however, select or create a different IP address pool. Note that the netmask is limited to a minimum of 16. How to add a definition is explained on the Definitions & Users > Network Definitions > Network Definitions page.

    Policy: Select the IPsec policy for this IPsec connection. IPsec policies can be defined on the Remote Access > IPsec > Policies tab.

    Authentication type: Select the authentication type for this remote gateway definition. The following types are available:

    Enable XAUTH (optional): Extended authentication should be enabled to require authentication of users against configured backends.

    Automatic firewall rules (optional): This option is only available with the authentication type X.509 Certificate. By selecting this option you can automatically add firewall rules that allow traffic for this connection. The rules are added as soon as the connection is enabled, and they are removed when the connection is disabled.

    Comment (optional): Add a description or other information.

  3. Click Save.

    The new remote access rule appears on the Connections list.

To either edit or delete a remote access rule, click the corresponding buttons.

Related Topics Link IconRelated Topics
© 2019 Sophos Limited Sophos UTM 9.600