User guide

Configuring Virtual Private Networks
132 WatchGuard Firebox X Edge
uses DVCP to keep the VPN tunnel configuration. You use the name
Managed VPN because the Management Server manages the VPN
tunnel and sends the VPN configuration to your Edge. This makes
the Edge administrator’s task easy because you must type only a
small quantity of information into the Edge configuration pages.
You must have WatchGuard System Manager and a Firebox III, Fire-
box X Core, or Firebox X Peak to have a Management Server. When
your Firebox X Edge gets its VPN configuration from a Management
Server, your Edge is a client of the Management Server in a client-
server relationship. The Edge gets all of its VPN configuration from
the Management Server.
Setting up a Firebox X Edge for managed VPN
You use a different procedure if your Firebox X Edge has a static
external IP address than for an Edge with a dynamic external IP
address.
Setting up managed VPN on an Edge with dynamic
external IP address
If your Firebox X Edge has a dynamic IP address assigned to its
external interface, use this procedure to configure it as an endpoint
for managed VPN tunnels to a Firebox III or Firebox X and Watch-
Guard System Manager 8.0:
1 To connect to the System Status page, type https:// in the
browser address bar, and the IP address of the Edge trusted
interface.
The default URL is: https://192.168.111.1.
2 From the navigation bar, select Administration > VPN Manager
Access
The VPN Manager Access page appears.