Configuring Policy for Remote Access VPN
Configuring Policy for Remote Access VPN
Step 1 - Create a Security Gateway/Cluster object
- Install the required Security Gateway / Cluster Members and configure their interfaces.
For more information, see the R82 Installation and Upgrade Guide.
- In SmartConsole, create a new object.
For more information, see the R82 Security Management Administration Guide.
Establish the Secure Internal Communication (SIC).
Get the interfaces and configure their topology settings.
For more information, see the R82 Gaia Administration Guide.
Step 2 - Configure the required Remote Access VPN settings in the Security Gateway / Cluster object
Create a Security Gateway network object.
On the General Properties page, select VPN.
Initialize a secure communication channel between the VPN module and the Security Management Server by clicking Communication.
On the Topology page, define the interfaces and the VPN domain.
The ICA automatically creates a certificate for the Security Gateway.
Step 3 - Configure the applicable Host, Network, Group, User and Access Role objects
Step 4 - Configure the Remote Access VPN Community
From the Objects Bar, click VPN Communities.
Double-click RemoteAccess.
The Remote Access window opens.
On the Participating Gateways page, click the Add button and select the Security Gateways that are in the Remote Access Community.
On the Participating User Groups page, click the Add button and select the group that contains the Remote Access users.
Click OK.
Publish the changes.
Step 5 - Configure the applicable Access Control rules
These rules apply to traffic from the Remote Access VPN clients to internal resources behind the Security Gateway.
| Column | Description |
|---|---|
| Source | Select the applicable Host, Network, Group, User, and Access Role objects. |
| Destination | Select the applicable Host, Network, and Group objects. |
| VPN | Select the Remote Access VPN Community object. |
| Services & Applications | Select only the specific service objects to make the rule as restrictive as possible. |
| Action | Select the applicable action. |
Example:
| Source | Destination | VPN | Services & Applications | Action |
|---|---|---|---|---|
| Office_Mode_Network | MyWebServer | RemoteAccess | http https |
Accept |
Step 6 - Install the Access Control Policy
In SmartConsole, install the Access Control Policy on the Security Gateway/Cluster object.
Step 7 - Optional: Advanced Configuration
The encryption properties of the VPN tunnels in a Remote Access community are set by default. You can modify the encryption processes globally for all users, or configure the properties per user.
To modify the VPN tunnel encryption properties globally:
From Menu, click Global Properties.
From the navigation tree, click Remote Access > VPN- Authentication and Encryption.
Select an Encryption Method:
- IKEv2 only
| | | | --- | --- | | | Important - If you select this option, Remote Access clients that do not support IKEv2 cannot connect to the VPN Gateway. |
- Prefer IKEv2, support IKEv1
Remote Access clients that support IKEv2 use IKEv2 to connect to the VPN Gateway. Remote Access clients that do not support IKEv2 use IKEv1 to connect to the VPN Gateway.
- IKEv1 only (selected by default)
From the Encryption algorithms section, click Edit.
In the IKE Security Association (Phase 1) tab, configure the applicable settings:
- Support encryption algorithms - Select the encryption algorithms that will be supported with remote hosts.
- Use encryption algorithms - Choose the encryption algorithm that will have the highest priority of the selected algorithms. If given a choice of more than one encryption algorithm to use, the algorithm selected in this field will be used.
- Support Data Integrity - Select the hash algorithms that will be supported with remote hosts to ensure data integrity.
- Use Data Integrity - The hash algorithm chosen here will be given the highest priority if more than one choice is offered.
- Support Diffie-Hellman groups - Select the Diffie-Hellman groups that will be supported with remote hosts.
- Use Diffie-Hellman group - Client users utilize the Diffie-Hellman group selected in this field.
Click OK.
Install policy.
To configure encryption policies for specified users:
Open Global Properties, and click Remote Access > Authentication and Encryption.
From the Encryption algorithms section, click Edit.
In the Encryption Properties window, click the IPSEC Security Association (Phase 2) tab.
Clear Enforce Encryption Algorithm and Data Integrity on all users.
Click OK and close the Global Properties window.
For each user:
From the Objects Bar, double-click the user.
From the navigation tree, click Encryption.
Click Edit.
The IKE Phase 2 Properties window is displayed.
Click the Encryption tab.
Click Defined below.
Configure the Encryption Algorithm and Data Integrity.
Click OK and close the User Properties window.
Install policy.
23 October 2025