Configure access interfaces for a remote access VPN policy
The Access Interface table lists the interface groups and security zones that contain the device interfaces. These are configured for remote access SSL or IPsec IKEv2 VPN connections. The table displays the name of each interface group or security zone, the interface trustpoints used by the interface, and whether Datagram Transport Layer Security (DTLS) is enabled.
Procedure
Step 1 | Choose . | ||
Step 2 | Click the edit icon next to the remote access VPN policy and click the Access Interface tab. | ||
Step 3 | To add an access interface, click +. In the Add Access Interface dialog box, configure these parameters: | ||
Step 4 | In Access Settings, configure these parameters:
| ||
Step 5 | In SSL Settings, configure these parameters:
| ||
Step 6 | In IPsec-IKEv2 Settings, choose an identity certificate from the IKEv2 Identity Certificate drop-down list. | ||
Step 7 | In Service Access Control, choose a service access object from the Service Access Object drop-down list or click + to create a new object. You can use a service access object to control remote clients' access to VPN on Firewall Threat Defense devices with Version 7.7 or later. This object provides geolocation-based access control to clients before VPN authentication. By default, there is no access control for RA VPN, and remote clients can connect from any geolocation unless specified by a service access object. For more information, see Configure VPN access of remote users based on geolocation and Configure a service access object. | ||
Step 8 | In Access Control for VPN Traffic section, select this option to bypass access control policy:
| ||
Step 9 | Click Save. |