Define endpoints for External VPN Gateways
Each endpoint is dedicated for one External VPN Gateway element.
Before you begin
You must have an External VPN Gateway element.
For more details about the product and how to configure features, click Help or
press F1.
Steps
- Right-click the External VPN Gateway element, then select Properties.
- On the Endpoints tab, click Add.
-
Configure the following optional settings according to your environment if needed.
- (Optional) In the Name field, enter a descriptive name for the endpoint.
-
(Policy-Based VPNs only) From the Connection Type drop-down list, select an option to define how the endpoint is used in a Multi-Link configuration.
You can override these settings in each individual VPN.
-
(Optional) From the Use NAT-T drop-down list, select an option to activate encapsulation for NAT traversal in site-to-site VPNs.
You might need NAT traversal to traverse a NAT device at the local or at the remote gateway end. The gateway always allows VPN clients to use NAT-T regardless of these settings. NAT-T always uses the standard UDP port 4500.Note: If a private external IP address is translated to a public IP address by an external NAT device, make sure that Contact Addresses and Locations are defined for the Engine.
-
If necessary, change the default Contact Address or add Exceptions for the Locations of other gateways involved in the VPN.
The Contact Address must be defined if the IP address for contacting this gateway is different from the IP address that the gateway actually has on its interface (for example, because of NAT).Example: An external gateway is behind a NAT device. The real address is defined as the endpoint address, because the IP address is also used as the Phase 1 ID inside the encrypted traffic. Contact must be made using the translated address, so it is defined as a Contact Address.
-
In the Phase-1 settings, select an option from the ID Type drop-down list to according to your environment.
The ID identifies the Gateways during the IKE SA negotiations. The IP Address might not work as an ID if the address is translated using NAT.
-
In the ID Value field, enter an ID value according to the selected ID type.
- Distinguished Name to use Distinguished Name (DN) .
- IP Address to use SAN: IP address.
- DNS Name to use SAN: Fully Qualified Domain Name (FQDN).
- Email to use SAN: user FQDN.
Note: Make sure that the ID value matches the identity configured on the external gateway device. - Click OK to save your changes to the endpoint.