HELP
TABLE OF CONTENTS

VPN>Configure>GroupVPN with IKE using 3rd Party Certificates

GroupVPN allows for easy deployment of Global VPN Clients or Global Security Clients making it unnecessary to individually configure remote VPN clients.You must use the GroupVPN SA even if you have only one VPN client to deploy. SonicWALL GroupVPN SA supports three IPSec keying modes: IKE using shared secret, IKE using SonicWALL Certificates, and IKE using 3rd Party Certificates. The following steps explain how to create the GroupVPN SA using IKE using shared secret.

Once you create the GroupVPN SA, you configure GroupVPN to automatically provision SonicWALL Global VPN Clients by downloading the policy, or exporting the policy file for manual installation in the SonicWALL Global VPN Client.

The following instructions explain how to configure SonicWALL GroupVPN with IKE using 3rd Party Digital Certificates.

Configuring GroupVPN with IKE using 3rd Party Certificates

Alert! Before configuring GroupVPN with IKE using 3rd Party Certificates, your certificates must be installed on the SonicWALL.

  1. In the VPN>Configure page, select GroupVPN from the Security Association menu.

  1. Select IKE using 3rd Party Certificates from the IPSec Keying Mode menu.

  2. Select a certificate for the SonicWALL from the Select Certificate menu.

  3. If the Disable This SA box is checked, uncheck it.

Security Policy

  1. Select Group 2 from the Phase1 DH Group menu.

  2. Leave the default setting, 28800, in the SA Life time (secs) field. This setting forces the tunnel to renegotiate and exchange keys every 8 hours.

  3. Select 3DES & SHA1 from the Phase1 Encryption/Authentication menu.

  4. Select Strong Encrypt and Authenticate (ESP 3DES HMAC SHA1) from the Phase 2 Encryption/Authentication menu.

Peer Certificates

  1. Select Distinguished Name, E-Mail ID, or Domain Name from the Peer ID Type menu:

  2. Enter the peer ID filter in the Peer ID Filter field.

  3. Check All Only Peer Certificates Signed by Gateway Issuer, if

  4. Click Update to enable the changes.

Advanced Settings (Optional)

  1. Click Advanced Settings to open the VPN Advanced Settings window.

  2. Select any of the following options in the VPN Advanced Settings window that apply to your GroupVPN SA:

Tip! If network connection speed is an issue, select Group 1. If network security is an issue, select Group 5. To compromise between speed and security, select Group 2.

  1. Click OK.

  2. Click Update to enable the changes.

Client Settings

Clicking the Client Settings button in the Configure tab displays the VPN Client Settings window. The controls in this window allows configuration of Global VPN Client authentication requirements, username and password caching, use of DHCP Relay, and multi-connection behavior.

  1. Click Client Settings. The VPN Client Settings window appears.

  2. Select any of the following boxes that you want to apply to Global VPN Client provisioning:

User Name and Password Caching

Client Connections

Client Initial Provisioning

  1. Click OK.

  2. Click Update to enable the changes.

Export Settings

To export the GroupVPN settings to a file, click on the Export Settings button in the Configure tab to display the Export Security Association window. The controls in this window allow you to export the SA to a file. SonicWALL Global VPN Client users import this file using the New Connection Wizard.

To export the GroupVPN SA to a file,

  1. Click the Export Settings button in the Configure tab to display the Export Security Association window.

  2. Select rcf format is required for SonicWALL Global VPN Clients. Files saved in the rcf format can be password encrypted.

  3. Click Yes. The VPN Policy Export window appears.

  4. Type a password in the Password box and reenter it in the Confirm Password box, if you want to encrypt the exported file. If you choose not to enter a password, the exported file is not encrypted.

  5. Click Submit. If you did not enter a password, a message window appears confirming your choice.

  6. Click OK. The File Download window appears showing the default filename.

  7. Save the file.

  8. Click Close.

The security file can be saved to a floppy disk or e-mailed to a remote VPN client. The SA must be enabled on the SonicWALL to export the configuration file.

Help Table of Contents