To add a new IPSEC VPN, click the VPN->IPSEC menu on the Interface screen.
Here;
Local Network is assumed to be 192.168.1.0/24 and 192.168.10.0/24.
Remote center/branch external IP address is assumed to be 219.41.59.66 and Remote Local Network 192.168.2.0/24.
Let's start configuring the settings of our new vpn by clicking Add.
NOTE: IPSEC creates a secure connection between branches. Here it is assumed that the center and branch have static IPs. If you do not have a static IP, you cannot use this feature.
1- On the screen that opens, fill in the VPN Definition, Remote Server, Interface, Dead Pear Detective fields in the Network tab.
2- Switch to the Authentication tab, here Configuration type default IKEv1 is selected. Protocol, Mode, Exchange Mode are selected as shown in the image. Peer ID type can be IP or FQDN, Peer ID field can be left blank. Key field is mandatory. (Your configuration here must be the same as the other center/branch).
3- Switch to Phase-1 tab, here Encryption, Hash, Group, Key Validity Period can be selected as shown in the image. Local ID type can be IP or FQDN, Local ID field can be left blank. (Your configuration here must be the same as the other center/branch).
4- Switch to Phase-2 tab, where Local Networks is your own local network. Remote Tunnel Networks is the local network on the opposite center/branch side. If you want which of your local networks to access the counter local network, you need to add them below as shown in the image. Encryption, Hash, Group, Key Validity Period can be selected as in the image. (Your configuration here must be the same as the other center/branch).
5- Switch to the Advanced tab, here you can type an IP address in the local network against the Ping Control field or leave it blank. The Auto Add Firewall Rules option must be active. If you activate the Failover option, when your current line goes down, the other line you select here will continue to keep the connection active.
6- Switch to the Validity tab, where you can select the hours during which the IPSEC VPN will be active. By default the ALWAYS option is active.
After you click Save, you need to configure the same settings you configured here for the counter center/branch.
NOTE: You can define the External IP address of the counter center/branch in Definitions->Safe IP.
