<< Configure the GRE Tunnel

Create IPsec Proposal >>

 

Example 5: GRE over IPsec, Site-to-Site, with Manual Keying

Create Named Objects

For this example, you will need address objects for the local and remote gateways, VLAN70 and VLAN40, and a service object for the GRE protocol. The objects on each site can have any name that you want.

TMS zl Module A

TMS zl Module B

  1. Select Firewall > Access Policies > Addresses.

  2. Click Add an Address.

  3. Create a single-entry network address for VLAN70.

  1. For Name, type VLAN70.

  2. For Type, select Network.

  3. Select Single-entry and type 10.1.70.0/24.

  4. Click Apply.

  1. Create a single-entry network address for VLAN40.

  1. For Name, type VLAN40.

  2. For Type, select Network.

  3. Select Single-entry and type 10.1.40.0/24.

  4. Click Apply.

  1. Create a single-entry IP address for the external interface on Site A.

  1. For Name, type siteAinter.

  2. For Type, select IP.

  3. Select Single-entry and type 172.23.99.99.

  4. Click Apply.

  1. Create a single-entry IP address for the external interface on Site B.

  1. For Name, type siteBinter.

  2. For Type, select IP.

  3. Select Single-entry and type 192.168.33.22.

  4. Click Apply.

  5. Click Close.

  1. Create a service object for GRE.

  1. Click the Services tab.

  2. Click Add Service.

  3. For Name, type gre.

  4. For Protocol, select (47) GRE.

  5. Click Apply.

  6. Click Close.

  1. Select Firewall > Access Policies > Addresses.

  2. Click Add an Address.

  3. Create a single-entry network address for VLAN40.

  1. For Name, type VLAN40.

  2. For Type, select Network.

  3. Select Single-entry and type 10.1.40.0/24.

  4. Click Apply.

  1. Create a single-entry network address for VLAN70.

  1. For Name, type VLAN70.

  2. For Type, select Network.

  3. Select Single-entry and type 10.1.70.0/24.

  4. Click Apply.

  1. Create a single-entry IP address for the external interface on Site B.

  1. For Name, type siteBinter.

  2. For Type, select IP.

  3. Select Single-entry and type 192.168.33.22.

  4. Click Apply.

  1. Create a single-entry IP address for the external interface on Site A.

  1. For Name, type siteAinter.

  2. For Type, select IP.

  3. Select Single-entry and type 172.23.99.99.

  4. Click Apply.

  5. Click Close.

  1. Create a service object for GRE.

  1. Click the Services tab.

  2. Click Add Service.

  3. For Name, type gre.

  4. For Protocol, select (47) GRE.

  5. Click Apply.

  6. Click Close.

<< Configure the GRE Tunnel

Create IPsec Proposal >>