Setting Up Site-To-site VPN R80.x
Setting Up Site-To-site VPN R80.x
x
Author: Danny Drake
Table of Contents
SITE TO SITE VPN IN R80.X............................................................................................................................................. 1
INTRODUCTION ............................................................................................................................................................. 2
SITE TO SITE VPN SETTINGS ........................................................................................................................................... 3
VPN WITH A THIRD PARTY .......................................................................................................................................... 13
COMMON SKS FOR TROUBLESHOOTING S2S VPNS ..................................................................................................... 16
2. Then open the gateway object you are installing the VPN tunnel on and enable the
IPSec VPN blade.
4. If your GWs external IP is different from the IP on the interface you are using for
your tunnel you will need to select the link manually. Open the drop down under
IPSec VPN and select Link Selection. Then select the Selected address from
topology table radial and select the interface you want to use.
7. There are two types of communities you could create; a Mesh community,
consisting of multiple gateways all being able to connect VPN to each other; or a
10. Next, choose the encryption method. This is where most of your troubleshooting
with 3rd party GWs will take place. The Encryption methods must be identical on
both ends. Use Aggressive mode if you are connecting to a 3rd party that does not
support Main mode. Use Perfect Forward Secrecy for extreme security needs as it
will affect performance.
12. Decide how the tunnel routes. Whether the satellites can go through the center or
just to it only.
14. You can choose certain traffic that will not be encrypted over the tunnel to increase
performance.
16. Wired mode simulates the GWs being connected together via wired connection,
bypassing the GW completely.
18. Next, you will create an Access Rule to allow the VPN traffic. You will add the
network/host objects in the destination and source. Choose the VPN community
you created, then allow and log the traffic.