Symantec 360R Administration Guide - Page 187

VPN field descriptions

Page 187 highlights

Field descriptions 187 VPN field descriptions Table C-24 Advanced tab field descriptions (Continued) Section IPSec Passthru Settings Exposed Host Field IPSec Type Enable Exposed Host LAN IP Address Description These values are used in ESP IPsec VPNs from some vendors for their software clients for IPsec pass-thru compatability. These settings do not apply to the VPN gateway on the security gateway. Keep this setting at 2 SPI unless instructed by Symantec Technical Support to change it. The None setting lets VPN clients be used in exposed host mode if it is having problems connecting from behind the security gateway. Options include: ■ 1 SPI ADI (Assured Digital) ■ 2 SPI Normal (Cisco Client, Symantec Client VPN, Nortel Extranet, Checkpoint SecureRemote) ■ 2 SPI-C (Cisco VPN Concentrator 30x0 series (formerly Altiga) ■ Others Redcreek Ravlin Client ■ None Use only for debugging clients. Check to enable an exposed host. Activate this feature only when required. This lets one computer on a LAN have unrestricted two-way communication with Internet servers or users. This feature is useful for hosting games or special server or application. IP address of the exposed host. If a host is defined as an exposed host, all traffic not specifically permitted by an inbound rule is automatically redirected to the exposed host. VPN field descriptions Virtual Private Networks (VPNs) let you securely extend the boundaries of your internal network to use insecure communication channels (such as the Internet)

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218

187
Field descriptions
VPN field descriptions
VPN field descriptions
Virtual Private Networks (VPNs) let you securely extend the boundaries of your
internal network to use insecure communication channels (such as the Internet)
IPSec Passthru
Settings
IPSec Type
These values are used in ESP IPsec VPNs from
some vendors for their software clients for IPsec
pass-thru compatability. These settings do not
apply to the VPN gateway on the security
gateway.
Keep this setting at 2 SPI unless instructed by
Symantec Technical Support to change it.
The None setting lets VPN clients be used in
exposed host mode if it is having problems
connecting from behind the security gateway.
Options include:
1 SPI
ADI (Assured Digital)
2 SPI
Normal (Cisco Client, Symantec Client VPN,
Nortel Extranet, Checkpoint SecureRemote)
2 SPI-C
(Cisco VPN Concentrator 30x0 series
(formerly Altiga)
Others
Redcreek Ravlin Client
None
Use only for debugging clients.
Exposed Host
Enable Exposed
Host
Check to enable an exposed host.
Activate this feature only when required. This
lets one computer on a LAN have unrestricted
two-way communication with Internet servers
or users. This feature is useful for hosting games
or special server or application.
LAN IP Address
IP address of the exposed host.
If a host is defined as an exposed host, all traffic
not specifically permitted by an inbound rule is
automatically redirected to the exposed host.
Table C-24
Advanced tab field descriptions (Continued)
Section
Field
Description