3.128. RoamingVPN

Description

This type of IPsec tunnel is used when you want to create VPN tunnels to roaming clients like mobile phones or laptops. The tunnel type is pre-configured to successfully connect with iOS, macOS and Windows clients using IKEv2 and EAP-MSCHAPv2. (IKEv2 and EAP-MSCHAPv2 is the default setting on most clients.)

Properties

Name
Specifies a symbolic name for the interface. (Identifier)
GatewayCertificate
Selects the certificate the firewall uses to authenticate itself to the other IPsec peer.
RootCertificates
Selects one or more root certificates to use with this IPsec Tunnel.
IPPoolAddress
Specifies the set of IP addresses to use for assigning IP addresses to VPN clients.
DNS
Specifies the IP address of a DNS server that a VPN client should be able to connect to. (Optional)
AuthSource
RADIUS or Local.
LocalUserDB
Specifies the local user database that will be used to authenticate users matching this rule.
RadiusServer
Specifies the authentication server that will be used to authenticate users.
SNMPIndex
Interface index assigned by the system when persistent interface indexes are enabled. (Default: 0)
Attribute
Special Attribute of the current object. (Optional)
MemberOfRoutingTable
All or Specific. (Default: All)
RoutingTable
Specifies the PBR table to insert the interface IP route into. It also means that the specified routing table will be used for all routing lookups, unless overridden by a PBR rule. (Default: main)
Zone
(Optional) Specifies the Zone that this interface is a member of. (Optional)
Comments
Text describing the current object. (Optional)