Symantec 16-00-00091 Installation Guide - Page 101

Dynamic tunnel, Symantec Firewall/VPN Dynamic tunnel configuration

Page 101 highlights

Dynamic tunnel Dynamic tunnel Dynamic tunnels differ from static tunnels in that both ends of the tunnel exchange the encryption keys dynamically. You do not have to configure these ahead of time. Figure 7-4: VPN Dynamic tunnel diagram Symantec Firewall/VPN Dynamic tunnel configuration On the Symantec Firewall/VPN appliance, select the VPN - Dynamic option from the configuration page. You should be presented with a screen similar to Figure 7-5 on page 7-8. Initially, the screen you see should be blank, with a few of the defaults entered. In order to properly configure a dynamic tunnel, you will need the following information from the SEVPN: • Gateway IP address of the SEVPN. • Shared Secret. • Destination network protected by the SEVPN. • Netmask of the destination network protected by the SEVPN. • Encryption parameters on SEVPN (DES, 3DES, SHA1, etc.) • Perfect Forward Secrecy setting. 7-7

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120

7-7
Dynamic tunnel
Dynamic tunnel
Dynamic tunnels differ from static tunnels in that both ends of the tunnel exchange the encryption
keys dynamically.
You do not have to configure these ahead of time.
Figure 7-4: VPN Dynamic tunnel diagram
Symantec Firewall/VPN Dynamic tunnel configuration
On the Symantec Firewall/VPN appliance, select the
VPN - Dynamic
option from the
configuration page.
You should be presented with a screen similar to
Figure 7-5 on page 7-8
.
Initially, the screen you see should be blank, with a few of the defaults entered.
In order to properly
configure a dynamic tunnel, you will need the following information from the SEVPN:
Gateway IP address of the SEVPN.
Shared Secret.
Destination network protected by the SEVPN.
Netmask of the destination network protected by the SEVPN.
Encryption parameters on SEVPN (DES, 3DES, SHA1, etc.)
Perfect Forward Secrecy setting.