Description
This type of IPsec tunnel is used when you want to create VPN tunnels to roaming clients like mobile phones or laptops. The
tunnel type is pre-configured to successfully connect with iOS, macOS and Windows clients using IKEv2 and EAP-MSCHAPv2. (IKEv2
and EAP-MSCHAPv2 is the default setting on most clients.)
Properties
- Name
- Specifies a symbolic name for the interface. (Identifier)
- GatewayCertificate
- Selects the certificate the firewall uses to authenticate itself to the other IPsec peer.
- RootCertificates
- Selects one or more root certificates to use with this IPsec Tunnel.
- IPPoolAddress
- Specifies the set of IP addresses to use for assigning IP addresses to VPN clients.
- DNS
- Specifies the IP address of a DNS server that a VPN client should be able to connect to. (Optional)
- AuthSource
- RADIUS or Local.
- LocalUserDB
- Specifies the local user database that will be used to authenticate users matching this rule.
- RadiusServer
- Specifies the authentication server that will be used to authenticate users.
- SNMPIndex
- Interface index assigned by the system when persistent interface indexes are enabled. (Default: 0)
- Attribute
- Special Attribute of the current object. (Optional)
- MemberOfRoutingTable
- All or Specific. (Default: All)
- RoutingTable
- Specifies the PBR table to insert the interface IP route into. It also means that the specified routing table will be used
for all routing lookups, unless overridden by a PBR rule. (Default: main)
- Zone
- (Optional) Specifies the Zone that this interface is a member of. (Optional)
- Comments
- Text describing the current object. (Optional)