TMS zl Management and Configuration Guide ST.1.1.100226

7-259
Virtual Private Networks
Configure a GRE over IPsec VPN with IKE
4. Allow GRE messages from the TMS zl Module to the remote tunnel
endpoint:
a. For Action, leave the default Permit Traffic.
b. For From, select Self.
c. For To, select the remote zone.
d. For Service, specify GRE.
e. For Source, leave Any Address or specify the IP address that you
configured for the local endpoint IP address.
f. For Destination, specify the public IP address of the remote tunnel
endpoint.
g. Click Apply.
5. If you are using IKE, allow IKE messages from the remote tunnel endpoint.
a. For Action, accept the default: Permit Traffic.
b. For From, select the remote zone.
c. For To, select Self.
d. For Service, select isakmp.
e. For Source, specify the IP address that you configured for the remote
gateway in the IKE policy.
You can select a previously configured address object or type the IP
address manually (click Options and select Enter custom IP, IP/mask or
IP-Range).
f. For Destination, leave Any Address or specify the IP address that you
configured for the local gateway in the IKE policy.