Wizards_VPN

Wizards > VPN Wizard

The VPN Policy Wizard walks you step-by-step through the configuration of GroupVPN on the SonicWALL. After the configuration is completed, the wizard creates the necessary VPN settings for the selected VPN policy. You can use the SonicWALL Management Interface for optional advanced configuration options.

Using the VPN Policy Wizard

  1. In the top right corner of the VPN > Settings page, click on VPN Policy Wizard.

  2. Click Next.

  3. In the VPN Policy Type page, select WAN GroupVPN and click Next.

  4. In the IKE Phase 1 Key Method page, you select the authentication key to use for this VPN policy:

  5. Note         If you select Use this Key, and leave the default key as the value, you must still distribute the key to your VPN clients.

  6. Click Next.

  7. In the IKE Security Settings page, you select the security settings for IKE Phase 2 negotiations and for the VPN tunnel. You can use the defaults settings.

  8. Warning         The SonicWALL Global VPN Client version 1.x is not capable of AES encryption, so if you chose this method, only SonicWALL Global VPN Client versions 2.x and higher will be able to connect.

  9. Click Next.

  10. In the User Authentication page, select if you want the VPN Users to be required to authenticate with the firewall when they connect. If you select Enable User Authentication, you must select the user group which contains the VPN users. For this example, leave Enable User Authentication unchecked.

  11. Note         If you enable user authentication, the users must be entered in the SonicWALL database for authentication. Users are entered into the SonicWALL database on the Users > Local Users page, and then added to groups in the Users > Local Groups page.

  12. Click Next.

  13. In the Configure Virtual IP Adapter page, select whether you want to use the SonicWALL’s internal DHCP server to assign each VPN client IP address from the LAN zone’s IP range. Therefore, when a user connects, it appears that the user is inside the LAN. Check the Use Virtual IP Adapter box and click Next.

  14. The Configuration Summary page details the settings that will be pushed to the SonicWALL when you apply the configuration. Click Accept to create your GroupVPN.

Connecting the Global VPN Clients

Remote SonicWALL Global VPN Clients install the Global VPN Client software. Once the application is installed, they use a connection wizard to setup their VPN connection. To configure the VPN connection, the client must have the following information:

Configuring a Site-to-Site VPN using the VPN Wizard

You use the VPN Policy Wizard to create the site-to-site VPN policy.

Using the VPN Wizard to Configure Preshared Secret

  1. On the System > Status page, click on Wizards.

  2. In the Welcome to the SonicWALL Configuration Wizard page select VPN Wizard and click Next.

  3. In the VPN Policy Type page, select Site-to-Site and click Next.

  4. In the Create Site-to-Site Policy page, enter the following information:

  5. If you do not check this option, the peer must initiate contact to create a VPN tunnel. This device will use aggressive mode for IKE negotiation.

    For this example, leave the option unchecked.

  6. Click Next.

  7. In the Network Selection page, select the local and destination resources this VPN will be connecting:

If the object or group you want has not been created yet, select Create Object or Create Group. Create the new object or group in the dialog box that pops up. Then select the new object or group. For this example, select LAN Subnets.

  1. Select Create new Address Group.

  2. In the Name field, enter “LAN Group”.

  3. In the list on the left, select LAN Subnets and click the -> button.

  4. Click OK to create the group and return to the Network Selection page.

  5. In the Destination Networks field, select the newly created group.

  6. Click Next.

  7. In the IKE Security Settings page, select the security settings for IKE Phase 2 negotiations and for the VPN tunnel. You can use the default settings.

  8. The Configuration Summary page details the settings that will be pushed to the security appliance when you apply the configuration.

  9. Click Accept to create the VPN.