Quick Reference Guide

ProSafe Wireless-N VPN Firewall SRXN3205 Reference Manual
6-12 Virtual Private Networking Using IPsec
v1.0, January 2010
Managing IPsec VPN Policies
After you use the VPN Wizard to set up a VPN tunnel, a VPN policy and an IKE policy are stored
in separate policy tables. The name you selected as the VPN tunnel connection name during
Wizard setup identifies both the VPN policy and IKE policy. You can edit existing policies, or add
new VPN and IKE policies directly in the policy tables.
Managing IKE Polices
The IKE (Internet Key Exchange) protocol performs negotiations between the two VPN gateways,
and provides automatic management of the keys used in IPsec. It is important to remember the
following:
“Auto” generated VPN policies must use the IKE negotiation protocol.
“Manual” generated VPN policies cannot use the IKE negotiation protocol.
Figure 6-12
Note: You cannot modify an IKE policy that is associated with an enabled VPN policy.
To modify the IKE policy, first disable the VPN policy. After you have modified
and saved the IKE policy, you can then re-enable the VPN policy.