TMS zl Management and Configuration Guide ST.1.0.090213

7-129
Virtual Private Networks
Configure Firewall Access Policies for Your VPN
d. For Service, specify the object that you configured for GRE.
e. For Source, leave Any Address or specify an actual module IP address
on a TMS VLAN that the remote endpoint can reach.
This is the IP address configured as the local address in the GRE
tunnel. It is different from the address configured on the subnet
reserved for the tunnel.
f. For Destination, specify the actual IP address of the remote tunnel
endpoint.
This is the IP address configured as the remote address is the GRE
tunnel. It is different from the address configured on the subnet
reserved for the tunnel.
g. Click Apply.
7. Permit local traffic that is sent across the tunnel:
a. For Action, leave the default, Permit Traffic.
b. For From, select the local zone.
c. For To, select the tunnel zone.
d. For Service, leave Any Service.
This is the most basic configuration. You could also create access
policies that allow only certain types of traffic.
e. For Source, specify the local IP addresses that are allowed to send
traffic on the tunnel.
f. For Destination, specify the subnet that you specified in the tunnel
traffic selector.