Symantec 360R Administration Guide - Page 89

The Symantec Gateway Security 300 Series can connect to another Symantec

Page 89 highlights

Establishing secure VPN connections 89 Configuring Gateway-to-Gateway tunnels The appliance supports Gateway-to-Gateway tunnel configurations. A Gatewayto-Gateway configuration is created when two security gateways are connected, through an internal network, or the Internet, from WAN port to WAN port. Figure 6-1 Gateway-to-Gateway VPN tunnel configuration This type of network configuration usually connects two subnets on the same network, or as shown in Figure 6-1, two remote offices through the Internet. Once a VPN tunnel is established, users protected by a security gateway at one site can establish a tunneled connection to the security gateway protecting the remotely located site. The remote user can connect to and access the resources of the private network as if the remote workstation was physically located inside the protected network. The Symantec Gateway Security 300 Series can connect to another Symantec Gateway Security 300 Series appliance or to one of the following appliances: ■ Symantec Gateway Security 5400 Series ■ Symantec Firewall/VPN Appliance Symantec Gateway Security 300 Series security gateways support creating a VPN tunnel to up to five remote subnets behind Symantec Enterprise Firewall or Symantec Gateway Security 5400 Series appliances, but not to another Symantec Gateway Security 300 Series appliance or Symantec Firewall/VPN Appliance. Tunnels between two Symantec Gateway Security 300 Series appliances are only made to the subnet on the LAN side of the appliance and only support the first set (subnet/mask) of the five sets of fields, which you define on the VPN > Dynamic Tunnels or VPN > Static Tunnels tabs.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218

89
Establishing secure VPN connections
Configuring Gateway-to-Gateway tunnels
The appliance supports Gateway-to-Gateway tunnel configurations. A Gateway-
to-Gateway configuration is created when two security gateways are connected,
through an internal network, or the Internet, from WAN port to WAN port.
Figure 6-1
Gateway-to-Gateway VPN tunnel configuration
This type of network configuration usually connects two subnets on the same
network, or as shown in
Figure 6-1
, two remote offices through the Internet.
Once a VPN tunnel is established, users protected by a security gateway at one
site can establish a tunneled connection to the security gateway protecting the
remotely located site. The remote user can connect to and access the resources
of the private network as if the remote workstation was physically located inside
the protected network.
The Symantec Gateway Security 300 Series can connect to another Symantec
Gateway Security 300 Series appliance or to one of the following appliances:
Symantec Gateway Security 5400 Series
Symantec Firewall/VPN Appliance
Symantec Gateway Security 300 Series security gateways support creating a
VPN tunnel to up to five remote subnets behind Symantec Enterprise Firewall or
Symantec Gateway Security 5400 Series appliances, but not to another
Symantec Gateway Security 300 Series appliance or Symantec Firewall/VPN
Appliance. Tunnels between two Symantec Gateway Security 300 Series
appliances are only made to the subnet on the LAN side of the appliance and
only support the first set (subnet/mask) of the five sets of fields, which you
define on the VPN > Dynamic Tunnels or VPN > Static Tunnels tabs.