HELP
TABLE OF CONTENTS

VPN>Configure>IKE using Preshared Secret

Internet Key Exchange IKE transparently negotiates encryption and authentication keys. The two SonicWALL appliances authenticate the IKE VPN session by matching preshared keys and IP addresses or Unique Firewall Identifiers.

Configuring IKE using Preshared Secret

  1. Select -Add New SA- from the Security Association menu.

  2. Select IKE using Preshared secret from the IPSec Keying Mode menu.

  3. Enter a descriptive name for the Security Association, such as "Palo Alto Office" or "NY Headquarters", in the Name field.

  4. Make sure the Disable This SA box is unchecked to enable this VPN policy.

  5. Enter the primary VPN gateway address in the IPSec Primary Gateway Name or Address field. You can add a secondary VPN gateway address in the IPSec Secondary Gateway Name or Address field. This address must be valid, and should be the NAT Public IP Address if the remote SonicWALL uses Network Address Translation (NAT). If the remote SonicWALL uses a dynamic IP address, you can enter "0.0.0.0" in the IPSec Gateway Address field or you can enter the dynamic IP address of the remote SonicWALL. With SonicWALL's Flexible VPN feature, the remote SonicWALL initiates IKE negotiation in Aggressive Mode because it has a dynamic IP address, and authenticates using the SA Names and Unique Firewall Identifiers rather than the IP addresses. Therefore, the SA Name for the SonicWALL must match the opposite SonicWALL Unique Firewall Identifier.

Security Policy

  1. Select Main Mode from the Exchange menu.

  2. Select Group 2 from the Phase 1 DH Group menu.

  3. Define the length of time before an IKE Security Association automatically renegotiates in the SA Life time (secs) field.

Tip! A short SA Life Time increases security by forcing the two VPN gateways to update the encryption and authentication keys. However, every time the VPN tunnel renegotiates, users accessing remote resources are disconnected. Therefore, the default SA Life Time of 28,800 seconds (8 hours) is recommended.

  1. Select the 3DES or AES-128, AES-192, or AES 256 options from the Phase1 Encryption/Authentication menu.

  2. Select the Authenticate, Encrypt and Authenticate, Stong Encrypt, or Strong Encrypt and Authenticate options from the Phase 2 Encryption/Authentication menu.
  3. Enter an alphanumeric “secret” in the Shared Secret field. The Shared Secret must match the corresponding field in the remote SonicWALL. This field can range from 4 to 128 characters in length and is case sensitive.

Destination Networks

  1. Select Use this SA as the default route for all Internet traffic if all remote VPN connections access the Internet through this SA. You can only configure one SA to use this feature. If you do not select this feature, go to Step 13.

  2. Select Destination network obtains IP addresses using DHCP through this SA if the remote network obtains its IP addresses from this SA. If you do not select this feature, go to Step 13.

  3. Select Specify destination networks below if the VPN destination is a specific IP address and click Add New Network. The VPN Destination Network window is displayed.

  4. Click Update to enable all your VPN policy changes.

Advanced Settings (Optional)

  1. Click Advanced Settings and select the boxes that apply to your SA:

Tip! If network connection speed is an issue, select Group 1. If network security is an issue, select Group 5. To compromise between speed and security, select Group 2.

  1. Click OK to close the Advanced Settings window.
  2. Click Update to apply the changes to the SonicWALL.

Delete This SA

Click Delete This SA to delete the current SA. A dialog box is displayed asking you to confirm the deletion of this VPN policy. Click OK to proceed with the deletion.

Help Table of Contents