Setup access rules to decrypt traffic from remote VPN clients

Steps

  1. Select Engine Configuration.
  2. Browse to Engine > Policies > Engine Policies.
  3. Right-click the Engine policy that is used by the Security Engines involved in the VPN, then select Edit Engine Policy.
  4. Add an IPv4 Access rule in a suitable location in the policy and configure the rule as outlined here:
    Table 1. Example VPN rule
    Source Destination Service Action Authentication
    Network element that represents the virtual IP address range for the VPN Client Networks or hosts of the local site Set as needed. Right-click the Action cell, and then select the Edit option. Set VPN Action to Enforce VPN, then select a Policy-Based VPN.

    Users: The User Group or User elements

    Authentication Methods: Client Certificate

  5. Save the policy.
  6. Refresh the policies of all firewalls involved in the VPN to activate the new configuration.