HP TMS zl Module Security Administrator's Guide

4-154
Configuring a VPN on the HP TMS zl Module
Configuring an IPsec Site-to-Site VPN with IKE
Figure 4-98. Deploy Site-to-Site VPN > Configure Local Networks for Hub and
Spoke 1
13. For Protocol (Action: Allow), specify the protocol for traffic allowed on the
VPN:
Any—Any IP protocol. Select this option when you want to allow all
traffic between local and remote endpoints.
TCP or UDP—Select one of these options when you want to restrict
this VPN to carrying certain TCP or UDP services.
IP Protocols—The list includes IANA IP Protocols. Select one of these
Layer 3 protocols when you want to restrict this VPN to carrying that
protocol.
Service objects and service groups will not appear in this list.
14. Under Local Network Address on Hub, specify the IP addresses of all Site 1
endpoints that are allowed to send traffic over the VPN (indicated by 2 in
the figure).