The security device uses proxy IDs to route the traffic if multiple tunnels exist between the peers. This page allows you to configure multiple proxy IDs on a route-based VPN and provides the following information about each proxy ID:
Local: Specifies the details of the host or subnet (end entity) behind the local security device.
Remote: Specifies the details of the host or subnet (end entity) behind the remote security device.
Service: Specifies the service permitted through the tunnel.
Configure: Click Edit to modify the entry, or click Remove to delete it.
Note: You cannot configure multiple proxy IDs on a policy-based VPN.
To Create a New Proxy IDLocal: Select Local IP or Local Address. To configure a proxy ID, you can use either an IP address or the address name of a local device.
Local IP
IP: Specify the local IP address that sends and receives the traffic through the tunnel.
Netmask: The netmask of the specified local IP address.
Local Address
Zone: Select the zone to which the local address that sends and receives the traffic through the tunnel is bound.
Address: Select the local address name from the drop-down list.
Remote: Select Remote IP or Remote Address. You should select the same option used for Local. For example, if you have used IP format to enter the local device details, you should select Remote IP.
Remote IP
IP: Specify the remote IP address that sends and receives the traffic through the tunnel.
Netmask: The netmask of the specified remote IP address.
Remote Address
Zone: Select the zone to which the remote address that sends and receives the traffic through the tunnel is bound.
Address: Select the remote address name from the drop-down list..
Service: Select the service that you want to permit through the VPN tunnel.
Click New to save your changes.