How to do it...

  1. Navigate to VPN | IPsec.
  2. Click on the Mobile Clients tab.
  3. Check the Enable IPsec Mobile Client Support checkbox:

  1. In the User Authentication listbox, select Local Database.
  2. In the Group Authentication drop-down menu, select system.
  3. Check the Provide a virtual IP address to clients checkbox.
  4. Enter a network and CIDR for the virtual address pool.
  5. Check the Save Xauth Password checkbox.
  6. Check the DNS Default Domain checkbox, and enter localdomain as the default domain.
  7. Check the Provide a DNS server list checkbox and enter 1.1.1.1 and 1.0.0.1 as the DNS servers.
  8. Check the Login Banner checkbox and enter an appropriate login banner.
  9. When you are done, click on the Save button.
  10. When the page reloads, click the Create Phase 1 button.
  11. Keep the Key Exchange set to IKEv1.
  12. Set the Authentication Mode to Mutual PSK + XAuth.
  13. Change Peer identifier to User distinguished name. Enter something unique for this field, such as an email address.
  14. In the Pre-Shared key text field, enter an appropriate pre-shared key.
  15. Scroll down to Advanced Options, and change NAT Traversal to Force. This will force the use of NAT-T on port 4500.
  16. When you are done, click on Save.
  17. When the page reloads, click on Apply Changes.
  18. Click on the Show Phase 2 Entries for the newly created mobile client phase 1 entry. This should reveal the Add P2 button for the newly created connection.
  19. Click on the Add P2 button.
  20. Most of the default values on the Edit Phase 2 page can be kept at their default values. It is recommended, however, that you change the Encryption Algorithm to AES256-GCM, and that you change the Hash Algorithm to SHA256.
  1. When you are done making changes, click on the Save button.
  2. Phase 1 and phase 2 configuration is complete; now we must add one or more users via the User Manager. Navigate to System | User Manager to begin the process. First, add a group for VPN users:
    1. Click on the Groups tab.
    2. Click on the Add button to add a new group.
    3. Enter a group name of vpnusers:

    1. In the Scope drop-down menu, select Remote.
    2. Click on the Save button.
    3. When the page reloads, the vpnusers group should be listed in the table. Click on the Edit icon for vpnusers.
    4. There will now be a section on the configuration page for the group called Assigned privileges. Click on the Add button in this section.
    5. In the Assigned privileges box, select User – VPN: IPsecxauthDialin and click on Save:

    1. On the main configuration page, click on Save.
  1. Now we can add users to the vpnusers group, which we can do by clicking on the Users tab:
    1. From the Users tab, click on the Add button.
    2. Set an appropriate Username and Password combination for the new user.

    1. Under Group Memberships, select the vpnusers group.
    2. For the IPsec Pre-Shared Key, enter the key you entered during phase 1 configuration.
    3. Click on the Save button.
    4. Repeat these steps for as many users as you wish to add.
..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
18.219.208.117