Add a rule or rules to encrypt traffic from the local site to the remote site
Steps
-
Select
Engine
Configuration.
- Browse to Engine > Policies > Engine Policies.
- Right-click the Engine policy that is used by the Security Engines involved in the VPN, then select Edit Engine Policy.
-
Add two IPv4 or IPv6 Access rules in a suitable location in the policy.
- Make sure that rules for sending traffic through the VPN are above other rules that match the same traffic the Allow, Discard, or Refuse action.
- Traffic that you do not want to send through the VPN must not match these rules. Traffic that is not routable through the VPN is dropped if it matches these rules.
-
Fill in the rules as outlined here. If NAT is enabled in the VPN, remember that the Access rules are checked before the NAT rules are applied.
Table 1. Example VPN rules Source Destination Service Action Networks or hosts of the local site Networks or hosts of the remote site Set as needed. Select Allow, then open the Action options. Set VPN Action to Enforce VPN, then select a Policy-Based VPN. Remote internal networks Local internal networks Set as needed. Select Allow, then open the Action options. Set VPN Action to Enforce VPN, then select a Policy-Based VPN. - Save the policy.
- Refresh the policies of all firewalls involved in the VPN to activate the new configuration.