TMS zl Management and Configuration Guide ST.1.2.100916

7-298
Virtual Private Networks
Configure a GRE over IPsec VPN with Manual Keying
h. For Destination, specify the appropriate multicast address.
If you specified a particular service, you can also leave Any Address if
you choose.
i. Click Apply.
2. Configure an access policy to permit remote multicast traffic that arrives
on the tunnel, after it is encapsulated:
a. Click Add Policy.
b. For Action, accept the default, Permit Traffic.
c. For From, select the local zone.
d. For To, select the tunnel zone.
e. For Service, accept the default, Any Service. This is the most basic
configuration. You could also permit only certain types of traffic.
f. For Source, specify the remote IP addresses that are allowed to send
traffic on the tunnel.
g. For Destination, specify the appropriate multicast address.
If you specified a particular service, you can also leave Any Address if
you choose.
h. Click Apply.
3. If you enabled a dynamic routing protocol (RIP or OSPF) on the tunnel,
ensure that access policies permit this traffic between SELF and the
tunnel zone. (This is the default setting.)
4. Click Close.
5. Click Save.