Define a VPN site for remote private networks

You must define site elements for all Security Engines and external VPN gateways that are used in policy-based VPNs.

The Site elements must always contain the actual IP addresses that are used inside the VPN tunnel. If traffic in the tunnel is subject to NAT, you must add the NAT addresses to the site. For Security Engines, you must add both the NAT addresses and any untranslated IP addresses that are not automatically added to the site. Sites for External VPN Gateways only require the translated address space that the Security Engine actually contacts.

The local and remote site definitions must match the same information about the other gateways involved in the VPN because the gateways verify this information during IKE negotiation. When creating VPNs with external Gateways, make sure that the IP address spaces of both gateways are defined identically in the SMC and on the external device. Otherwise, the VPN establishment can fail in one or both directions. Make sure to update the policies of any firewalls that are involved in the VPN when there are changes in the Site elements at either end.

If you want to use a central gateway as a hub that forwards traffic from one VPN tunnel to another, include all IP addresses that are accessible through the central gateway in the central gateway’s Site elements.

Note: You cannot add or change Site elements under the VPN Client Gateway element.

For more details about the product and how to configure features, click Help or press F1.

Steps

  1. Select Secure SD-WAN Configuration.
  2. Browse to VPN Gateways.
  3. Right-click External VPN Gateway, then select New > Site.
  4. Select the elements that represent the protected IP addresses behind the Gateway, then click Add to include them in this site.
    • Do not include IP addresses outside the Gateway’s local networks in the site. There is no need to include the Gateways’ own IP addresses in the sites. However, there is usually no need to exclude those addresses if they are in the networks you add to the site.
    • IP address ranges might be interpreted differently from lists of IP addresses and networks depending on the VPN device. The system converts Group or Expression elements into address ranges, networks, or individual IP addresses depending on the IP addresses included. Other VPN devices might treat the same types of values differently.
    • VPN Traffic Selector elements allow you to define the IP addresses, protocols, and ports used by a specific host in a VPN site.
  5. Click OK.