jerome_itable Lv2Posted 24 Nov 2023 09:20
  
Here are the steps for both the Headquarters and Branch configurations:

Headquarters Configuration

    Enable VPN Service: Go to Network > IPSec VPN > Status and click Enable VPN Service.

    Add VPN Paths: Go to Basic Settings > VPN Paths > Add. Select the WAN interface you want to use for VPN and specify the public IP address that will be used for VPN (changing the ISP name has no effect).

    Add Third-Party Connection: Go to Third-Party Connection to use for IPSec VPN and click Add Connection. You will need to fill in the following information:
        VPN Connection Name: Enter a name for the VPN connection.
        Peer IP Address: Enter the public IP address of the Branch NGAF.
        Authentication Method: Select Pre-Shared Key.
        Shared Key: Enter a shared key that will be used for authentication.
        Local Line: Select the local line that is the same as the outgoing line of one interface.
        Enable Aggressive Mode: Select this option if you want to use aggressive mode for the VPN connection. Aggressive mode can improve performance, but it is less secure than main mode.

    Save the configuration: Click Save to save the configuration.

Branch Configuration

    Enable VPN Service: Go to Network > IPSec VPN > Status and click Enable VPN Service.

    Add VPN Paths: Go to Basic Settings > VPN Paths > Add. Select the WAN interface you want to use for VPN and specify the public IP address that will be used for VPN (changing the ISP name has no effect).

    Add Third-Party Connection: Go to Third-Party Connection to use for IPSec VPN and click Add Connection. You will need to fill in the following information:
        VPN Connection Name: Enter a name for the VPN connection.
        Peer IP Address: Enter the public IP address of the Headquarters NGAF.
        Authentication Method: Select Pre-Shared Key.
        Shared Key: Enter the shared key that was used for authentication in the Headquarters configuration.
        Local Line: Select the local line that is the same as the outgoing line of one interface.
        Enable Aggressive Mode: Select this option if you want to use aggressive mode for the VPN connection. Aggressive mode can improve performance, but it is less secure than main mode.

    Save the configuration: Click Save to save the configuration.

Testing the VPN Connection

    Go to Network > IPSec VPN > Status.

    Click on the VPN connection that you created.

    The VPN connection status should be Established.

You can now test the VPN connection by trying to access resources on the other network.

Additional Notes

    You may need to configure firewall rules on both the Headquarters and Branch NGAFs to allow VPN traffic.

    If you are using dynamic IP addresses, you will need to use a dynamic DNS service to keep the public IP addresses of the Headquarters and Branch NGAFs up to date.

    If you are using aggressive mode, you may need to increase the MTU on the WAN interfaces of the Headquarters and Branch NGAFs to 1458.

I hope this helps!

I Can Help:

Change

Moderator on This Board

0
2
4

Started Topics

Followers

Follow

67
14
3

Started Topics

Followers

Follow

3
1
2

Started Topics

Followers

Follow

1
131
3

Started Topics

Followers

Follow

Board Leaders