Print topic

Configure the Firebox or XTM Device for Mobile VPN with IPSec

You can use Policy Manager to enable Mobile VPN with IPSec for a group of users you have already created, or you can create a new user group. The users in the group can authenticate either to the Firebox or XTM device, or to a third-party authentication server included in your Firebox or XTM device configuration.

For more information about how to add users to a group for local Firebox authentication, see Add Users to a Firebox Mobile VPN Group. If you use a third-party authentication server, follow the instructions provided in the documentation from its manufacturer.

  1. Select VPN > Mobile VPN > IPSec.
    The Mobile VPN with IPSec Configuration dialog box appears.

Screen shot of the Mobile VPN with IPSec Configuration dialog box

  1. Click Add.
    The Add Mobile User VPN with IPSec Wizard appears.

Screen shot of the Add Mobile VPN with IPSec Wizard first screen

  1. Click Next.
    The Select a user authentication server screen appears.

Screen shot of the Select a user authentication server dialog box

  1. From the Authentication Server drop-down list, select an authentication server.

You can authenticate users to the Firebox or XTM device (Firebox-DB) or to a RADIUS, VASCO, SecurID, LDAP, or Active Directory server. Make sure that this method of authentication is enabled in Policy Manager. Select Setup > Authentication > Authentication Servers to see these settings.

  1. In the Group Name text box, type the name of the group.

You can type the name of a Mobile VPN group you have already created, or enter a group name for a new Mobile VPN group. Make sure the name is unique among VPN group names, as well as all interface and tunnel names.

For more information about VPN group authentication, see Types of Firebox Authentication.

  1. Click Next.
    The Select a tunnel authentication method screen appears.

Screen shot of the Select a tunnel authentication method wizard dialog box

  1. Select an option for tunnel authentication:
  1. Click Next.
    The Direct the flow of Internet traffic screen appears.

Screen shot of the Direct the flow of Internet traffic wizard dialog box

  1. Select an option for Internet traffic:

For more information about split tunneling and default-route VPN, see Options for Internet Access Through a Mobile VPN with IPSec Tunnel.

  1. Click Next.
    The Identify the resources accessible through the tunnel screen appears.

Screen shot of the Identify the resources accessable through the tunnel wizard dialog box

  1. Click Add to specify the host or network IP addresses that users can connect to through the VPN tunnel.
  2. Click Next.
    The Create the virtual IP address pool screen appears.

Screen shot of the Create the virtual IP address pool wizard dialog box

  1. Click Add to add one IP address or an IP address range.
    To add more virtual IP addresses, repeat this step.

Mobile VPN users are assigned one of these IP addresses when they connect to your network. The number of IP addresses should be the same as the number of Mobile VPN users. If High Availability is configured, you must add two virtual IP addresses for each Mobile VPN user. The IP addresses cannot be used for anything else on your network.

  1. Click Next.
    The Add Mobile VPN with IPSec Wizard has completed successfully screen appears.

Screen shot of the Add Mobile VPN with IPSec Wizard, Completed Successfully dialog box

    The Mobile VPN with IPSec group end-user configuration file is available at the location specified on this screen.

  1. To add users to the new Mobile VPN with IPSec group, select the Add users to check box.
  2. Click Finish.

Give us feedback  •   Get Support  •   All product documentation  •   Knowledge Base