Using ipsec_tunnel with WatchGuard Firebox System 5.0
In "Policy Manager" select Network->Branch Office VPN->Manual IPSec.
Adding a gateway
- Open the "Configure gateways" dialog by clicking "Gateways..." and
- then select "Add..".
- Enter a name and set key negotiation type to manual.
- Enter the IP address of the remote gateway. (your ipsec_tunnel box)
- Click OK.
- Close the "Configure Gateways" dialog.
Adding a tunnel
- From the "IPSec Configuration" dialog select "Tunnels...".
- Select the gateway you just created.
- Give the tunnel a name.
- Switch to the "Manual Security" tab and click on "Settings...".
- Enter SPI (decimal).
- Select 3DES-CBC encryption.
- Enter the encryption key in hex (48 digits).
- Set "Authentication" to none.
- Make sure that "Use Incoming settings for Outgoing" is checked.
- Click OK.
- Close the "Configure Tunnels" dialog.
Adding routing policies
- From the "IPSec Configuration" dialog select "Add...".
- Enter the local and remote host/network you want to access thru the
tunnel.
- Set "Disposition" to secure.
- You can optionally select source/destination port and/or protocol (tcp/udp).
- Click OK.
- Repeat if necessary.
- Close the "IPSec Configuration" dialog.