Define VPN client settings for Secure SD-WAN Engines
VPN client settings in the Engine Editor define the settings that are used when the Secure SD-WAN Engine acts as a VPN Gateway in a mobile VPN.
If you use Forcepoint VPN Client, configure the Virtual Adapter. The alternative NAT Pool method does not allow the Forcepoint VPN Client computers to use your organization’s internal DNS servers. Virtual IP addresses work with all Forcepoint VPN Client versions and with third-party VPN clients that support this feature.
If you use Forcepoint VPN Client, the policy-based VPN configuration defined in the Management Client is also used for creating the configuration for Forcepoint VPN Client. Forcepoint VPN Client downloads the settings from the VPN gateway the first time that the Forcepoint VPN Client connects to the VPN Gateway, and automatically whenever there are relevant changes. All IPsec and address management settings are included in the download. For example, the download includes information about which encryption methods are used, which VPN endpoints are available, and which internal networks clients can access through the gateway. The decision whether a VPN tunnel is used is based on the IP addresses you have defined for the Sites of the gateway.
- All IPsec-related settings, such as the authentication, encryption, and integrity checking options.
- The encryption domain (the IP addresses that are allowed in the VPN as a source or destination IP address).
If a VPN Gateway that contains VPN Client settings is used in a route-based VPN, the VPN Client settings are ignored.
For more details about the product and how to configure features, click Help or press F1.
Steps
Engine Editor > SD-WAN > VPN Client
Use this branch to change settings that are used when the Secure SD-WAN Engine acts as a VPN Gateway in a mobile VPN.
Option | Definition |
---|---|
Gateway Display Name | If you want to show a different name for the Gateway to Mobile VPN users, enter the name for the VPN Gateway element. |
SD-WAN Type | Defines the type of tunnels the mobile VPN supports.
|
SSL Port | (When SD-WAN Type is SSL VPN) The port for SSL VPN tunnels. |
TLS Cryptography Suite Set | (When SD-WAN Type is SSL VPN) The cryptographic suite for SSL VPN tunnels. Click Select to select an element.Note: Do not change the default setting unless you have a specific reason to do so.
|
Authentication Timeout | (When SD-WAN Type is SSL VPN) The timeout for Forcepoint VPN Client user authentication. |
Option | Definition |
---|---|
Local Security Checks section (Forcepoint VPN Client for Windows only) | Defines whether the Forcepoint VPN Client for Windows checks for the presence of basic security software to stop connections from risky
computers.
|
Option | Definition |
---|---|
Virtual Address section | Options for configuring the Forcepoint VPN Client with virtual IP addresses assigned by a DHCP server for connections inside the VPN. |
DHCP Mode | Specifies how DHCP requests from VPN clients are sent.
Note: If
SSL VPN or
Both IPsec & SSL VPN is selected from the
SD-WAN Type drop-down list, only the
Direct and
DHCP Relay are shown.
|
Interface | (When DHCP Mode is Direct) The source address for the DHCP packets when querying the DHCP server (the interface toward the DHCP server). |
Interface for DHCP Relay | (When DHCP Mode is Relay) The source address for the DHCP packets when querying the DHCP server (the interface toward the DHCP server). |
DHCP Server (Secure SD-WAN < 5.9) | (When DHCP Mode is Direct) The DHCP server that assigns IP addresses for the VPN clients.Note: This option is included for backward compatibility with legacy software versions.
|
DHCP Servers | (When DHCP Mode is Relay) The DHCP server that assigns IP addresses for the VPN clients. Click Add to add an element to the table, or Remove to remove the selected element. |
Add Information
(Optional) |
Specifies what VPN Client user information is added to the Remote ID option field in the DHCP Request packets.
|
Restrict Virtual Address Ranges | When selected, the VPN gateway restricts the VPN clients’ addresses to the specified range, even if the DHCP server tries to assign some other IP address. Enter the IP address range in the field on the right. |
Proxy ARP | When selected, the engine acts as a proxy for the VPN clients’ ARP requests. Enter the IP address range for proxy ARP in the field on the right. |
Option | Definition |
---|---|
Secondary IPsec VPN Gateways section (Optional) |
(When SD-WAN Type is IPsec VPN) Other IPsec VPN gateways to contact in case there is a disruption at the IPsec VPN gateway end (in the order of contact). Click Add to add a row to the table, or Remove to remove the selected row. Click Up or Down to move the selected element up or down. |