Create External VPN Gateway elements
In the Management Client, create two External VPN Gateway elements to represent the cloud end of each connection.
The connections are used in an active-active configuration.
For more details about the product and how to configure features, click Help or
press F1.
Steps
-
Select
Configuration, then browse to SD-WAN.
- Browse to VPN Gateways.
-
Create an External VPN Gateway element to represent the cloud end of the first VPN tunnel.
-
Select
New > External VPN Gateway.
-
In the Name field, enter a descriptive name.
Example: Private Access Tunnel 1Note: Do not close the External VPN Gateway Properties dialog box.
-
Select
-
Configure endpoints for the first external VPN gateway.
-
On the Endpoints tab, click Add.
-
Configure the following settings:
- Name — (Optional) Enter a descriptive name, such as the same name that you provided for this connection in the Private Access management portal.
- IP Address — Enter the value of the Tunnel destination IP address for the first tunnel from the Private Access management portal.
- Connection Type — Select Active.
- NAT-T — Select Enabled.
- Phase-1 ID — From the ID Type drop-down list, select DNS Name. In the ID Value field, enter the value of the Forcepoint IKE ID from the Private Access management portal.
-
Click OK.
-
In the Enabled column, select the checkbox for the endpoint.
Note: Do not close the External VPN Gateway Properties dialog box.
-
On the Endpoints tab, click Add.
-
Configure a site for the first external VPN gateway.
- On the Sites tab, browse to Hosts in the left pane.
- Select the Host element that represents the NAT IP address of the first tunnel, then click Add.
- Click OK.
The configuration of the first external VPN gateway is complete. -
Create an External VPN Gateway element to represent the cloud end of the second VPN tunnel.
-
Select
New > External VPN Gateway.
-
In the Name field, enter a descriptive name.
Example: Private Access Tunnel 2Note: Do not close the External VPN Gateway Properties dialog box.
-
Select
-
Configure endpoints for the second external VPN gateway.
- On the Endpoints tab, click Add.
-
Configure the following settings:
- Name — (Optional) Enter a descriptive name, such as the same name that you provided for this connection in the Private Access management portal.
- IP Address — Enter the value of the Tunnel destination IP address for the second tunnel from the Private Access management portal.
- Connection Type — Select Active.
- NAT-T — Select Enabled.
- Phase-1 ID — From the ID Type drop-down list, select DNS Name. In the ID Value field, enter the value of the Forcepoint IKE ID from the Private Access management portal.
- Click OK.
-
In the Enabled column, select the checkbox for the endpoint.
Note: Do not close the External VPN Gateway Properties dialog box.
-
Configure a site for the second external VPN gateway.
- On the Sites tab, browse to Hosts in the left pane.
- Select the Host element that represents the NAT IP address of the second tunnel, then click Add.
- Click OK.
The configuration of the second external VPN gateway is complete.