Page 101 / 131
Scroll up to view Page 96 - 100
A more secure LAN-to-LAN VPN solution
Go get a more secure solution, policies should be created instead of allowing all traffic
between the two offices. The following steps will show how to enable some common services.
In this example we have a mail server, ftp server and a web server (intranet) in the main office
that we want to access from the branch office.
Settings for Branch office
1.
Setup policies for the new tunnel,
Firewall->Policy:
Click
Global policy parameters
Disable
Allow all VPN traffic: internal->VPN, VPN->internal and VPN->VPN
Click
Apply
2.
Now is it possible to create policies for the VPN interfaces. Select from
LAN
to
toMainOffice
and click
Show
.
3.
Click
Add new
to create the first rule
Page 102 / 131
102
4.
Setup the new rule:
Name the new rule:
allow_pop3
Select action:
Allow
Select service:
pop3
Select schedule:
Always
We don’t want any Intrusion detection or traffic shaping for now, so leave these
options unchecked.
Click
Apply
Page 103 / 131
5.
The first policy rule is now created. Repeat step 4 to create services named
allow_imap
,
allow_ftp
and
allow_http
. The services for these policies should be
imap
,
ftp_passthrough
and
http
.
The policy list for
LAN->toMainOffice
should now look like this.
6.
Click
Activate
and wait for the firewall to restart.
Page 104 / 131
104
Settings for Main office
1.
Setup policies for the new tunnel,
Firewall->Policy:
Click
Global policy parameters
Disable
Allow all VPN traffic: internal->VPN, VPN->internal and VPN->VPN
Click
Apply
2.
Now is it possible to create policies for the VPN interfaces. Select from
toBranchOffice
to
LAN
and click
Show
.
3.
Create same 4 policy rules as was created on the branch office firewall (
allow_pop3
,
allow_imap
,
allow_ftp
and
allow_http
).
4.
Click
Activate
and wait for the firewall to restart.
Page 105 / 131
Windows XP client and PPTP server
Settings for the Windows XP client
1.
Open the control panel (Start button -> Control panel).
2.
If you are using the Category view, click on the
Network and Internet Connections
icon. Then click
Create a connection to
the network on your workplace
and
continue to step 6.
If you are using the Classic view, click on the
Network Connections
icon.
3.
Under Network task, click
Create
a
new
connection
4.
The
New connection wizard
window opens up. Click
next
.