HP VPN Firewall Appliances VPN Configuration Guide

431
interface GigabitEthernet0/1. Enter VPN domain name vpn2. Enter the VAM server address
192.168.1.22. Enter the secondary VAM server address 192.168.1.33. Enter the VAM client
username dvpn2spoke2. Enter the VAM client password dvpn2spoke2. Enter the password
dvpn2spoke2 for confirmation. Enter the VAM client pre-shared key 456. Enter the key 456 for
confirmation.
c. Select Enable IPsec.
d. Select the IPsec authentication method Pre-Shared Key and then enter abcde in the field.
e. Select IP Address as both the remote ID type and the local ID type.
f. Click Apply.
4. Configure OSPF:
a. From the navigation tree, select Network > Routing Management > OSPF.
b. Select Enable OSPF and click Apply.
c. In the Area Configuration area, click Add.
d. Enter the area ID 0. Select Normal as the area type.
e. Enter the network address 192.168.4.0, select the network mask 0.0.0.255, and then click
Add Network.
f. Enter the network address 10.0.1.0, select the network mask 0.0.0.255, and then click Add
Network.
g. Enter the network address 10.1.4.0, select the network mask 0.0.0.255, and then c
lick Add
Network.
h. Enter the network
address 10.0.2.0, select the network mask 0.0.0.255, and then click Add
Network.
i. Enter the network address 10.1.6.0, select the network mask 0.0.0.255, and then click Add
Network.
j. Click Apply.
k. Click More>> to perform OSPF interface configuration.
l. Click the icon of interface Tunnel1.
m. Select Broadcast as the network type.
n. Select 0 as the DR priority.
o. Click Apply.
p. Repeat steps k through o to configure the same settings for interface Tunnel2.
Configuring Spoke 3
The Spoke 3 configuration page is similar to the Hub 1 configuration page. See the figures for Hub 1
configuration.
1. Configure tunnel interface Tunnel2 for VPN domain vpn2.
a. From the navigation tree, select VPN > DVPN > Client, and then click Add.
b. Select tunnel encapsulation mode GRE. Enter tunnel interface number 2. Enter IP address/mask
10.0.2.3/24. Select security zone Management for the tunnel interface. Select tunnel source
interface GigabitEthernet0/1. Enter VPN domain name vpn2. Enter the VAM server address
192.168.1.22. Enter the secondary VAM server address 192.168.1.33. Enter the VAM client
username dvpn2spoke3. Enter the VAM client password dvpn2spoke3. Enter the password
dvpn2spoke3 for confirmation. Enter the VAM client pre-shared key 456. Enter the key 456 for
confirmation.