Setup access rules to decrypt traffic from remote VPN clients
Steps
-
Select
Engine
Configuration.
- Browse to Engine > Policies > Engine Policies.
- Right-click the Engine policy that is used by the Security Engines involved in the VPN, then select Edit Engine Policy.
-
Add an IPv4 Access rule in a suitable location in the policy and configure the rule as outlined here:
Table 1. Example VPN rule Source Destination Service Action Authentication Network element that represents the virtual IP address range for the VPN Client Networks or hosts of the local site Set as needed. Right-click the Action cell, and then select the Edit option. Set VPN Action to Enforce VPN, then select a Policy-Based VPN. Users: The User Group or User elements
Authentication Methods: Client Certificate
- Save the policy.
- Refresh the policies of all firewalls involved in the VPN to activate the new configuration.