Netgear SRX5308 SRX5308 Reference Manual - Page 190

Table 5-16. Add IKE Policy Settings for a Mode Config Configuration

Page 190 highlights

ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Reference Manual Note: The settings that are explained in Table 5-16 are specifically for a Mode Config configuration. Table 5-10 on page 5-25 explains the general IKE policy settings. Table 5-16. Add IKE Policy Settings for a Mode Config Configuration Item Description (or Subfield and Description) Mode Config Record Do you want to use Mode Config Record? Select the Yes radio button. Note: Because Mode Config functions only in Aggressive mode, selecting the Yes radio button sets the tunnel exchange mode to Aggressive mode and disables the Main mode. Mode Config also requires that both the local and remote ends are defined by their FQDNs. Select Mode Config Record From the drop-down list, select the Mode Config record that you created in step 5 on page 5-46. In this example, we are using NA Sales. General Policy Name Direction / Type Exchange Mode A descriptive name of the IKE policy for identification and management purposes. In this example, we are using ModeConfigNA_Sales. Note: The name is not supplied to the remote VPN endpoint. Responder is automatically selected when you select the Yes radio button in the Mode Config Record section of the screen. This ensures that the VPN firewall responds to an IKE request from the remote endpoint but does not initiate one. Aggressive mode is automatically selected you select the Yes radio button in the Mode Config Record section of the screen. Local Select Local Gateway From the drop-down list, select one of the four WAN interfaces to function as the local gateway. Identifier Type From the drop-down list, select FQDN. Note: Mode Config requires that the VPN firewall (that is, the local end) is defined by an FQDN. Identifier Enter an FQDN for the VPN firewall. In this example, we are using srx_local2.com. 5-48 Virtual Private Networking Using IPsec Connections v1.0, April 2010

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384

ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Reference Manual
5-48
Virtual Private Networking Using IPsec Connections
v1.0, April 2010
Note:
The settings that are explained in
Table 5-16
are specifically for a Mode
Config configuration.
Table 5-10 on page 5-25
explains the general IKE
policy settings.
Table 5-16. Add IKE Policy Settings for a Mode Config Configuration
Item
Description (or Subfield and Description)
Mode Config Record
Do you want to use
Mode Config Record?
Select the
Yes
radio button.
Note
: Because Mode Config functions only in Aggressive mode, selecting the
Yes radio button sets the tunnel exchange mode to Aggressive mode and
disables the Main mode. Mode Config also requires that both the local and
remote ends are defined by their FQDNs.
Select Mode
Config Record
From the drop-down list, select the Mode Config record that
you created in
step 5
on
page 5-46
. In this example, we are
using NA Sales.
General
Policy Name
A descriptive name of the IKE policy for identification and management
purposes. In this example, we are using ModeConfigNA_Sales.
Note
: The name is not supplied to the remote VPN endpoint.
Direction / Type
Responder is automatically selected when you select the
Yes
radio button in
the Mode Config Record section of the screen. This ensures that the VPN
firewall responds to an IKE request from the remote endpoint but does not
initiate one.
Exchange Mode
Aggressive mode is automatically selected you select the
Yes
radio button in
the Mode Config Record section of the screen.
Local
Select Local Gateway
From the drop-down list, select one of the four WAN interfaces to function as
the local gateway.
Identifier Type
From the drop-down list, select
FQDN
.
Note
: Mode Config requires that the VPN firewall (that is, the local end) is
defined by an FQDN.
Identifier
Enter an FQDN for the VPN firewall. In this example, we
are using srx_local2.com.