In the Management Client, create a Policy-Based VPN element, and then define the topology and tunnel settings.
Steps
-
Select Configuration, then browse to SD-WAN.
-
Browse to Policy-Based VPNs.
-
Select .
-
In the Name field, enter a descriptive name.
Example: Forcepoint ONE VPN
-
Leave other fields as default and click OK.
The Policy-Based VPN opens for editing.
-
Configure the VPN topology.
Add the External VPN Gateway element as a central gateway and the VPN Gateway element that represents the NGFW Engine as a satellite
gateway.
-
In the pane on the left, browse to VPN Gateways.
-
Drag and drop the External VPN Gateway element to the Central Gateways list on the Site-to-Site VPN tab.
You can also create External VPN Gateway by right-clicking on the Central Gateways area under Site-to-Site VPN tab and then selecting
New External VPN Gateway from the drop-down menu.
-
Drag and drop the VPN Gateway element that represents the NGFW Engine to the Satellite Gateways list
on the Site-to-Site VPN tab.
-
On the Tunnels tab:
-
Double-click the Key field in Gateway-to-Gateway table.
-
Enter or paste the pre-shared key from of the Forcepoint ONE SSE portal.
-
Click Save to save the changes to the policy-based VPN.
Next steps
On your assigned NGFW Engine acting as Satellite Gateway in the policy-based VPN, verify that your local endpoint IKE ID matches what you
configured in the Forcepoint ONE SSE portal under tab.