MSM7xx Controllers Configuration Guide v6.4.0

Configure an IPSec policy for a remote VPN server
On the page Controller >> VPN > IPSec select Add New Policy and define a policy similar to this,
substituting your own IP addresses:
Note the selections made in the sample Add/Edit security policy page above.
NotesValue to setOption
EnabledGeneral
user-definedName
Main modePhase 1 mode
TunnelMode
Internet portInterface
Select as desiredEncryption algorithm
Leave enabledPerfect Forward Secrecy
DisabledAccept any peer
Set according to VPN server needs.
In this example, the VPN server
address is 3.1.1.1.
User-definedPeer information
Set according to VPN server needs.
Either the X.509 certificates or the
User-definedAuthentication method
Preshared key must match server
configuration.
Identify the local subnet for which
you wish to filter traffic, for example,
Identify the subnetSecurity policy > Only permit
incoming...
512 Working with VPNs