|
Navigate to the Services>Ipsec vpn>Ike level in
the configuration hierarchy.
|
- In the J-Web interface, select Configuration>View
and Edit>Edit Configuration.
- Next to Services, click Configure or Edit.
- Next to Ipsec vpn, click Configure.
- Next to Ike, click Configure.
|
From the [edit] hierarchy level, enter
edit services ipsec-vpn ike
|
|
Configure an IKE policy—for example, ike-dynamic-policy.
|
- Next to Policy, click Add new entry.
- In the Name box, type ike-dynamic-policy.
|
Enter
set policy ike-dynamic-policy
|
|
Configure a local ID for the policy—for example, 10.90.90.2.
|
- Next to Local id, click Configure.
- In the Id type box, select Ipv4 addr.
- In the Ipv4 addr box, type 10.90.90.2.
|
Enter
set policy ike-dynamic-policy local-id ipv4_addr 10.90.90.2
|
|
Configure a remote ID for the policy—for example, 10.90.90.1.
|
- Next to Remote id click Configure.
- Next to Ipv4 addr, click Add new entry.
- In the Value box, type 10.90.90.1.
|
Enter
set policy ike-dynamic-policy remote-id ipv4_addr 10.90.90.1
|
|
Configure a preshared key—for example, $1991poPPi—for
IKE in ASCII format.
Note:
The IKE preshared key must be configured exactly the same way at both
the local and remote endpoints of the IPSec tunnel.
|
- Next to Pre-shared key, click Configure.
- In the Key choice box, select Ascii text from
the list.
- In the Ascii text box, type the plain text IKE key $1991poPPi
|
Enter
set policy ike-dynamic-policy pre-shared-key ascii-text $1991poPPi
|
|
Configure the IKE proposal to be used for the IKE policy—for example, ike-dynamic-proposal.
|
- Next to Proposals, click Add new entry.
- In the Value keyword, type ike-dynamic-proposal.
- Click OK until you return to the main
Configuration page.
|
Enter
set policy ike-dynamic-policy proposals ike-dynamic-proposal
|