A VPN extends a secured private network over public networks by encrypting connections so that they can be transported over insecure links without compromising confidential data.
This guide provides the information you need to work with your Forcepoint product.
The SMC as a Service provides centralized access for configuring, managing, logging, and monitoring NGFWs that secure network connectivity and control business operations.
SMCaaS provides two types of VPNs. The main difference between the two is how traffic is selected to use the VPN.
You can create VPNs between VPN gateway devices or between a VPN client and a VPN gateway device.
In a mobile VPN, a VPN client on a user's device connects to a VPN gateway.
The Post-quantum Pre-Shared Key (PPK) is used in addition to the Diffie-Hellman (DH) key exchange in the IKEv2 protocol to prevent threats from quantum computers.
A Post-quantum Pre-shared Key (PPK) element can be used along with the IKEv2 protocol to prevent threats from quantum computers. A PPK consists of a Key ID and a Pre-shared secret.
SAs for IPsec VPNs are created in a process called the Internet key exchange (IKE) negotiations.
In route-based tunnels, the routing defines which traffic is sent through the tunnel.
An External VPN Gateway is any VPN gateway that is not controlled by the same SMCaaS Application on which you are configuring the gateway element.
The FEC feature helps to control errors in data transmission over an unreliable or noisy communication channel.
VPN negotiations and VPN traffic are logged as informational messages and can be viewed in the Logs view like any other logs.
A SMCaaS cluster can be used as a gateway in policy-based and route-based VPNs. There are no additional configuration steps compared to a Single Engine.
Using Multi-Link enhances the reliability of the VPN communications by ensuring the availability of network connections.
The VPN Broker creates highly-scalable, full-mesh VPN environments. VPN tunnels are automatically created between Engines when they communicate with each other. The VPN tunnels are automatically removed when they are no longer needed.
A digital certificate is a proof of identity. SMCaaS supports using certificates for authenticating gateways and the Forcepoint VPN Client.
You can reconfigure and tune existing VPNs.