Creating the secondary tunnel specification
- In the secondary system, on the NETWORK menu, under the VPN submenu, click IPsec subnets.
- Enter a descriptive Name for the tunnel and select Enabled to make sure that the tunnel can be started once configuration is completed.
- Select the external Local IP address to use for this tunnel and specify the Local network that the primary system can access. This should be given in the IP address/network mask format and should correspond to an existing local network. For example, 192.168.10.0/255.255.255.0.
- From the Local ID type list, select Local IP. This identifies the primary system to the secondary system by using the local IP address of the primary system’s external IP address.
- Leave Local ID value empty. It's generated automatically as Local IP was chosen as the local ID type.
- Enter the Remote IP or hostname of the primary system. Unlike the first tunnel specification, this can't be left blank. The secondary system acts as the initiator of the connection. Therefore, it needs a destination IP address to make first contact.
- Specify the Remote network on the primary system that the secondary system can access. This should be given in the IP address/network mask format and should correspond to an existing local network. For example, 192.168.10.0/255.255.255.0.
- From the Remote ID type list, select Remote IP (or ANY if blank Remote IP). This means that the primary system can use the secondary's IP address (if one was specified).
- Enter the Remote ID value of the secondary system and from the Authenticate by list, select "Preshared Key". This instructs the Smoothwall to authenticate the secondary system by validating a shared pass-phrase.
- Enter the same pass-phrase for the Preshared Key as was entered for the Preshared Key in the primary system and reenter it again to confirm it.
- Select the Use compression option if compression was turned on in the primary system.
- Select the Initiate the connection option if it's the responsibility of the secondary system to initiate its connection to the primary Smoothwall.
- Enter a descriptive Comment, for example, Tunnel to Head Office and click Add.
All advanced settings can be safely left at their defaults.