PnPVPN Configuration Example

This section describes an example of PnPVPN configuration.

A company has its headquarters in Beijing and two branch offices in Shanghai and Guangzhou, all three of which have Internet access. Its business demands that a VPN network should be established. The goals of the network are:

PnPVPN is a practical and easy-to-use method to meet the requirements above. Take the following steps:

The topology is shown below:

According to the topology, the network environment can be described as follows:

Take the steps below:

Step 1: Configure the local AAA server

  1. Select Objects > AAA Server from the menu bar.
  2. In the AAA Server dialog, click New and select Local Server from the drop-down list.
  3. In the Local Server Configuration dialog, type test into the Server name box.
  4. Click OK to save the settings. Click to close the dialog.

Step 2: Configure the network in Shanghai Branch

  1. Select Objects > AAA Server from the menu bar.
  2. In the Local User dialog, select test from the Local server list. Click New, and then select User from the drop-down list.
    On the Basic tab, configure the options as below:
    On the PnPVPN tab, configure the options as below:
  3. Click OK to save the settings.
  4. In the Local User dialog, select shanghai from the user list and click Edit. In the Edit User dialog, click the PnPVPN tab.
  5. Click Choose next to the Tunnel route box. In the Configuring Tunnel Route dialog, add the following routes: 192.168.200.0/24, 192.168.1.0/24 and 192.168.3.0/24.
  6. Click OK to save the settings. In the Edit User dialog, click OK.

Step 3: Configure the network in Guangzhou Branch

  1. In the Local User dialog, select test from the Local server list. Click New, and then select User from the drop-down list.
    On the Basic tab, configure the options as below:
    On the PnPVPN tab, configure the options as below:
  2. Click OK to save the settings.
  3. In the Local User dialog, select guangzhou from the user list and click Edit. In the Edit User dialog, click the PnPVPN tab.
  4. Click Choose next to the Tunnel route box. In the Configuring Tunnel Route dialog, add the following routes: 192.168.200.0/24, 192.168.1.0/24 and 192.168.2.0/24.
  5. Click OK to save the settings. In the Edit User dialog, click OK. Click to close the dialog.

Step 4: Configure PnPVPN Server

  1. On the Navigation pane, click Configure > Network > IPSec VPN to visit the IPSec VPN page. Click the Phase1 Proposal tab.
  2. Click New. In the Phase1 Proposal Configuration dialog, configure the options as below:
  3. Click OK to save the settings.
  4. Click the Phase2 Proposal tab.
  5. Click New. In the Phase2 Proposal Configuration dialog, configure the options as below:
  6. Click OK to save the settings.
  7. Click the VPN Peer List tab.
  8. Click New. In the Peer Configuration dialog, configure the options as below:
  9. Click Generate next to User key. In the Generate User Key dialog, use the following settings:
  10. Click OK to save the settings.
  11. Click the IPSec VPN tab.
  12. Click New on the upper-left of the IKE VPN list. In the IKE VPN Configuration dialog, click Import next to Peer name of Step 1: Peer and select test1 from the drop-down list. Or you can create a new peer (ISAMP gateway).
  13. Click Step 2: Tunnel to configure VPN tunnel. On the Basic tab, configure the options as below: On the Advanced tab, configure the options as below:
  14. Click OK to save the settings.

Step 5: Configure policies

  1. On the Navigation pane, click Configure > Network > Network to visit the Network page.
  2. Click New on the upper-left of the zone list. In the Zone Configuration dialog, configure the options as below:
  3. Click OK to save the settings.
  4. Click New on the upper-left of the interface list, and select Tunnel Interface from the drop-down list. In the Interface Configuration dialog, configure the options as below:
  5. Click OK to save the settings and return to the Network page.
  6. On the Navigation pane, click Configure > Security > Policy to visit the Policy page.
  7. Click New. In the Policy Configuration dialog, configure the options as below:
  8. Click OK to save the settings.
  9. In the Policy page, click New. In the Policy Configuration dialog, configure the options as below:
  10. Click OK to save the settings.
  11. In the Policy page, click New. In the Policy Configuration dialog, configure the options as below:
  12. Click OK to save the settings.

Step 6: Configure routes

  1. On the Navigation pane, click Configure > Network > Routing to visit the Routing page.
  2. On the Destination Route tab, click New. In the Destination Route Configuration dialog, configure the options as below:
  3. Click OK to save the settings.
  4. On the Destination Route tab, click New. In the Destination Route Configuration dialog, configure the options as below:
  5. Click OK to save the settings.

Step 7: Configure clients

Shanghai Branch

  1. On the Navigation pane, click Configure > Network > IPSec VPN to visit the IPSec VPN page to visit the IPSec VPN page.
  2. On the Task tab in the right auxilary pane, click PnPVPN Client. In the PnPVPN Configuration dialog, configure the options as below:
  3. Click OK to save your settings.

Guangzhou Branch

  1. On the Navigation pane, click Configure > Network > IPSec VPN to visit the IPSec VPN page to visit the IPSec VPN page.
  2. On the Task tab in the right auxilary pane, click PnPVPN Client. In the PnPVPN Configuration dialog, configure the options as below:
  3. Click OK to save your settings.