HELP
TABLE OF CONTENTS

VPN>Configure>GroupVPN with IKE using SonicWALL Certificates

The following instructions explain how to configure SonicWALL GroupVPN with IKE using SonicWALL Certificates.

Configuring GroupVPN with IKE using SonicWALL Certificates

Alert! Before configuring GroupVPN with IKE using SonicWALL Certificates, your certificates must be installed on the SonicWALL.

  1. In the VPN>Configure page, select GroupVPN from the Security Association menu.

  1. Select IKE using SonicWALL Certificates from the IPSec Keying Mode menu.

  2. If the Disable This SA box is checked, uncheck it.

Security Policy

  1. Select Group 2 from the Phase 1 DH Group menu.

  2. Type the SA time value in seconds in the SA Life time (sec) field. The default value of 28800 seconds (8 hours) is recommended.

  3. Select 3DES & SHA1 from the Phase 1 Encryption/Authentication menu.

  4. Select Strong Encrypt and Authenticate (ESP 3DES HMAC MD5) from the Phase 2 Encryption/Authentication menu.

  5. Type a Shared Secret in the Shared Secret box or use the Shared Secret automatically generated by the SonicWALL. If you enter a Shared Secret, the value should consist of a combination of letters and numbers. A Shared Secret is case-sensitive.

  6. Click Update to enable the changes.

Advanced Settings (Optional)

  1. Click Advanced Settings to open the VPN Advanced Settings window.

  2. Select any of the following options in the VPN Advanced Settings window that apply to your GroupVPN SA:

Tip! If network connection speed is an issue, select Group 1. If network security is an issue, select Group 5. To compromise between speed and security, select Group 2.

  1. Click OK.
  2. Click Update to enable the changes.

Client Settings

Clicking the Client Settings button in the Configure tab displays the VPN Client Settings window. The controls in this window allows configuration of Global VPN Client authentication requirements, username and password caching, use of DHCP Relay, and multi-connection behavior.

  1. Click Client Settings. The VPN Client Settings window appears.

  2. Select any of the following boxes that you want to apply to Global VPN Client provisioning:

User Name and Password Caching

Client Connections

Client Initial Provisioning

  1. Click OK.

  2. Click Update to enable the changes.

Export Settings

To export the GroupVPN settings to a file, click on the Export Settings button in the Configure tab to display the Export Security Association window. The controls in this window allow you to export the SA to a file. SonicWALL Global VPN Client users import this file using the New Connection Wizard.

To export the GroupVPN SA to a file,

  1. Click the Export Settings button in the Configure tab to display the Export Security Association window.

  2. Select rcf format is required for SonicWALL Global VPN Clients. Files saved in the rcf format can be password encrypted.

  3. Click Yes. The VPN Policy Export window appears.

  4. Type a password in the Password box and reenter it in the Confirm Password box, if you want to encrypt the exported file. If you choose not to enter a password, the exported file is not encrypted.

  5. Click Submit. If you did not enter a password, a message window appears confirming your choice.

  6. Click OK. The File Download window appears showing the default filename.

  7. Save the file.

  8. Click Close.

The security file can be saved to a floppy disk or e-mailed to a remote VPN client. The SA must be enabled on the SonicWALL to export the configuration file.

Help Table of Contents