HELP
TABLE OF CONTENTS

VPN>Configure>IKE using 3rd Party Certificates

To create a VPN SA with IKE using 3rd Party Certificates, follow these steps:

Configuring IKE using 3rd Party Certificates

  1. In the VPN>Configure page, select Add New SA from the Security Association menu.

  1. Select IKE using 3rd Party Certificates from the IPSec Keying Mode menu.

  2. Enter a Name for the Security Association in the Name field.

  3. Select a certificate from the Select Certificate list.

  4. Make sure the Disable This SA box is unchecked to enable this VPN policy.

  5. Enter the primary VPN gateway address in the IPSec Primary Gateway Name or Address field. You can add a secondary VPN gateway address in the IPSec Secondary Gateway Name or Address field. This address must be valid, and should be the NAT Public IP Address if the remote SonicWALL uses Network Address Translation (NAT). If the remote SonicWALL uses a dynamic IP address, you can enter "0.0.0.0" in the IPSec Gateway Address field or you can enter the dynamic IP address of the remote SonicWALL. With SonicWALL's Flexible VPN feature, the remote SonicWALL initiates IKE negotiation in Aggressive Mode because it has a dynamic IP address, and authenticates using the SA Names and Unique Firewall Identifiers rather than the IP addresses. Therefore, the SA Name for the SonicWALL must match the opposite SonicWALL Unique Firewall Identifier.

Security Policy

  1. Select Main Mode from the Exchange menu.

  2. Select Group 2 from the Phase1 DH Group menu.

  3. Leave the default setting, 28800, in the SA Life time (secs) field. This setting forces the tunnel to renegotiate and exchange keys every 8 hours.

  4. Select the 3DES or AES-128, AES-192, or AES 256 options from the Phase1 Encryption/Authentication menu.

  5. Select the Authenticate, Encrypt and Authenticate, Stong Encrypt, or Strong Encrypt and Authenticate options from the Phase 2 Encryption/Authentication menu.

Peer Certificate's ID

  1. Select the ID Type from the ID Type menu. You can select Distinguished Name, E-mail ID, or Domain Name from the menu. Then cut and paste the information from the Local Certificates page into the text field.

Destination Networks

  1. Select Use this SA as the default route for all Internet traffic if all remote VPN connections access the Internet through this SA. You can only configure one SA to use this feature. If you do not select this feature, go to Step 14.

  2. Select Destination network obtains IP addresses using DHCP through this SA if the remote network obtains its IP addresses from this SA. If you do not select this feature, go to Step 14.

  3. Select Specify destination networks below if the VPN destination is a specific IP address and click Add New Network. The VPN Destination Network window is displayed.

  4. Click Update to enable all your VPN policy changes.

Advanced Settings (Optional)

  1. Click Advanced Settings to open the VPN Advanced Settings window.

  2. Select any of the following options in the Advanced Settings window that apply to your GroupVPN SA:

Tip! If network connection speed is an issue, select Group 1. If network security is an issue, select Group 5. To compromise between speed and security, select Group 2.

  1. Click OK.

  2. Click Update to enable the changes.

Delete This SA

Click Delete This SA to delete the current SA. A dialog box is displayed asking you to confirm the deletion of this VPN policy. Click OK to proceed with the deletion.

Help Table of Contents