Quick Reference Guide

Table Of Contents
92 | Chapter 5: Virtual Private Networking Using IPsec
ProSafe Dual WAN Gigabit Firewall with SSL & IPsec VPN FVS336Gv2 Reference Manual
6. If you have a WINS Server on your local network, enter its IP address.
7. Enter one or two DNS Server IP addresses to be used by remote VPN clients.
8. If you enable Perfect Forward Secrecy (PFS), choose DH Group 1 or 2. This setting
must match exactly the configuration of the remote VPN client,
9. Specify the Local IP Subnet to which the remote client will have access. Typically, this is
your VPN firewall’s LAN subnet, such as 192.168.2.1/255.255.255.0. (If not specified, it
will default to the LAN subnet of the VPN firewall.)
10. Specify the VPN policy settings. These settings must match the configuration of the
remote VPN client. Recommended settings are:
SA Lifetime: 3600 seconds
Authentication Algorithm: SHA-1
Encryption Algorithm: 3DES
11. Click Apply.
The new record should appear in the List of Mode Config Records table on the Mode
Config screen.
Configuring an IKE Policy for Mode Config Operation
Next, you must configure an IKE policy:
1. Select VPN > IPsec VPN from the menu. The IKE Policies screen is displayed showing
the current policies in the List of IKE Policies table.
2. Click Add to configure a new IKE Policy. The Add IKE Policy screen is displayed: