This article describes how to configure Tunnel Interface VPN policies, which provide a route-based VPN solution. Tunnel Interface VPN policies differ from site to site VPN policies, which force the VPN policy configuration to include the network topology configuration. This makes it difficult to configure and maintain the VPN policy with a constantly changing network topology.
With the route-based VPN approach, network topology configuration is removed from the VPN policy configuration. The VPN policy configuration creates an unnumbered Tunnel Interface between two end points. Static or dynamic routes can then be added to the Tunnel Interface. The route-based VPN approach moves network configuration from the VPN policy configuration to static or dynamic route configuration. Route-based VPN makes configuring and maintaining the VPN policy easier, and provides flexibility on how traffic is routed.
NOTE: During the initial release, NSSP 13700 is only available in global mode. In a later release, SonicOSX with Policy mode will be available for selection.
This article explains how to configure route-based vpn on the NSSP 13700 and the required routes for the traffic flow:
Login to Site A (NSSP 13700 )
-on-NSSP-13700---kA1VN0000000MAG0A2-0EMVN00000EoNKp.png)
-on-NSSP-13700---kA1VN0000000MAG0A2-0EMVN00000EoNKr.png)
Click the Proposals Tab.
-on-NSSP-13700---kA1VN0000000MAG0A2-0EMVN00000EoNKn.png)
Click Advanced tab.
Follow the same set of Instructions on the Site B Firewall (NSSP 13700) and specify the public Host name or IP address of the ( NSSP 13700 Site). Please ensure the proposals are set as same on the remote site as specified on the Site A.
-on-NSSP-13700---kA1VN0000000MAG0A2-0EMVN00000EoNKw.png)
Creating a Static Route for the Tunnel Interface on Site A NSSP 13700
-on-NSSP-13700---kA1VN0000000MAG0A2-0EMVN00000EoNL2.png)
-on-NSSP-13700---kA1VN0000000MAG0A2-0EMVN00000EoNL0.png)
-on-NSSP-13700---kA1VN0000000MAG0A2-0EMVN00000EoNKz.png)
Route Policy will be displayed as shown below:
-on-NSSP-13700---kA1VN0000000MAG0A2-0EMVN00000EoNL4.png)
Configure the similar route policy on the Remote NSSP 13700 following the steps listed before.