Define endpoints for VPN Gateway elements

Each endpoint is dedicated for one VPN Gateway element.

Any IP address that is already an endpoint for another VPN Gateway element is not shown on the Endpoints list for other Gateways that you create for the same Security Engine. Each VPN Gateway element can be used in several policy-based VPNs or route-based VPN tunnels. However, you cannot use the same pair of local and remote endpoints in different VPN configurations for the same Security Engine.

For more details about the product and how to configure features, click Help or press F1.

Steps

  1. Right-click the Engine, then select Edit Single Engine or Edit Cluster Engine.
  2. Browse to VPN > Endpoints.
  3. (Optional) Change the selection of IP addresses that you want to use as endpoints in VPNs.
    • Typically, these are IP addresses that belong to interfaces toward the Internet, which are automatically selected based on the Engine’s default routing table.
    • If loopback IP addresses are defined for the Security Engine, you can select a loopback IP address as the endpoint IP address. On clustered firewalls, the IP addresses are CVIs.
    • (Optional) If you have more than one Internet connection, select an IP address from each ISP.
  4. Double-click the endpoint, then configure the following optional settings according to your environment.
    1. (Optional) In the Name field, enter a descriptive name for the endpoint.
    2. (Multi-Link tunnels only) From the Connection Type drop-down list, select the Connection Type element that defines how the endpoint is used in a Multi-Link configuration.
      You can override these settings in each individual VPN.
    3. (Optional) From the Use NAT-T drop-down list, select an option to activate encapsulation for NAT traversal in site-to-site VPNs.
      You might need NAT traversal to traverse a NAT device at the local or at the remote gateway end. The gateway always allows VPN clients to use NAT-T regardless of these settings. NAT-T always uses the standard UDP port 4500.
      Note: If a private external IP address is translated to a public IP address by an external NAT device, make sure that Contact Addresses and Locations are defined for the Engine.
  5. In the Phase-1 ID settings, select an option from the ID Type drop-down list according to your environment.
    The ID identifies the Gateways during the IKE SA negotiations.
  6. In the ID Value field, enter an ID value according to the selected ID type.
    • Distinguished Name to use Distinguished Name (DN). To include an email address in the DN, use the emailAddress attribute.
    • IP Address to use SAN: IP address.
    • DNS Name to use SAN: Fully Qualified Domain Name (FQDN)
    • Email to use SAN: user FQDN.
  7. (Optional) If the endpoint must use different Phase-1 ID settings in individual policy-based VPNs, add VPN-specific exceptions.
    1. Click Exceptions.
    2. Click Add, then select the type of ID from the drop-down list.
    3. Select a Policy-Based VPN element, then click Select.
    4. In the ID Value cell, enter the value of the ID.
    5. Click OK.
  8. In the VPN Type settings, restrict the types of VPNs that the endpoint can be used in.
    1. Select Selected types only.
    2. Select IPsec VPN only.
  9. Click OK to save your changes to the endpoint.
  10. Save the changes.
    • To save the changes, click Save.
    • To save the changes and refresh the security policy on the engine, click Save and Refresh.