Quick Reference Guide

ProSafe Wireless-N VPN Firewall SRXN3205 Reference Manual
Virtual Private Networking Using IPsec 6-27
v1.0, January 2010
5. Click Apply to save your settings. The VPN policy is added to the List of VPN Policies table.
To edit a VPN policy:
1. Select VPN > IPsec VPN from the main/submenu. The IPsec VPN submenu tabs appear with
the IKE Policies screen in view (see Figure 6-13 on page 6-13).
2. Click the VPN Policies tab. The VPN Policies screen is displayed (see Figure 6-15 on page
6-21).
3. In the List of VPN Policies table, click the edit button to the right of the VPN policy that you
want to edit. The Edit VPN Policy screen displays. This screen shows the same field as the
Add VPN Policy screen (see Figure 6-16 on page 6-23).
4. Modify the settings that you wish to change (see Table 6-4).
Click Apply to save your changes. The modified VPN policy is displayed in the List of VPN
Policies table.
Assigning IP Addresses to Remote Users (Mode Config)
To simplify the process of connecting remote VPN clients to the VPN firewall, use the Mode
Config feature to assign IP addresses to remote users, including a network access IP address,
subnet mask, WINS server, and DNS address from the VPN firewall. Remote users are given IP
addresses available in a secured network space so that remote users appear as seamless extensions
of the network.
PFS Key Group Select this checkbox to enable Perfect Forward Secrecy (PFS), and then select a
Diffie-Hellman (DH) group from the pull-down menu. The DH Group sets the
strength of the algorithm in bits. The higher the group, the more secure the
exchange. From the pull-down menu, select one of the following three strengths:
Group 1 (768 bit).
Group 2 (1024 bit). This is the default setting.
Group 5 (1536 bit).
Select IKE Policy Select an existing IKE policy that defines the characteristics of the Phase-1
negotiation. Click the view selected button to display the selected IKE policy.
Table 6-4. Add VPN Policy Settings (continued)
Item Description (or Subfield and Description)