TMS zl Management and Configuration Guide ST.1.0.090213

7-119
Virtual Private Networks
Configure Firewall Access Policies for Your VPN
d. For Service, select isakmp.
e. For Source, accept the default, Any Address.
If you know the public addresses of all of your remote endpoints, you
could create a named object with those addresses and specify that
object here. However, allowing any IP address is the easiest way to
set up the VPN. IKE will provide authentication, ensuring that only
the correct endpoints can connect.
f. For Destination, leave Any Address or specify the IP address that you
configured for the local gateway.
Figure 7-92. Add Policy Window
g. Click Apply.
4. Allow IKE messages to the remote endpoints.
a. For Action, leave the default Permit Traffic.
b. For From, select Self.
c. For To, select the remote zone.
d. For Service, select isakmp.
e. For Source, leave Any Address or specify the IP address that you
configured for the local gateway.