Use the information from your worksheets to configure VPN on Gateway-B
as follows:
- In iSeries™ Navigator, expand
your .
- Right-click Virtual Private Networking and
select New Connection to start the Connection wizard.
- Review the Welcome page for information
about what objects the wizard creates.
- Click Next to go to the Connection
Name page.
- In the Name field, enter CHIgw2MINhost.
- Optional: Specify a description for this connection group.
- Click Next to go to the Connection
Scenario page.
- Select Connect your gateway to another host .
- Click Next to go to the Internet
Key Exchange Policy page.
- Select Create a new policy and then select Balance
security and performance .
Note: If you get an error
message stating "The certificate request could not be processed" you can ignore
it because you are not using certificates for the key exchange.
- Optional: If you have certificates installed you will see the Certificate
for Local Connection Endpoint page. Select No to indicate that
you will be using certificates to authenticate the connection.
- Click Next to go to the Local
Key Server page.
- Select IP version 4 as the Identifier
type field.
- Select 214.72.189.35 from the IP address field.
- Click Next to go to the Remote
Key Server page.
- Select IP version 4 address in the Identifier
type field.
- Enter 146.210.18.51 in the Identifier field.
Note: Gateway B is initiating a connection to a Static NAT you must
specify main mode key exchange in order to enter a single IP for the remote
key. Main mode key exchange is selected by default when you create a connection
with the VPN Connection Wizard. If aggressive mode is used in this situation,
a non IPV4 type of remote identifier must be entered fro remote key.
- Enter topsecretstuff in the Pre-shared
key field
- Click Next to go to the Local
Data Endpoint page.
- Select IP version 4 subnet from the Identifier
type field.
- Enter 10.8.0.0 in the Identifier field.
- Enter 255.255.255.0 in the Subnet mask field.
- Click Next to go to the Data
Services page.
- Accept the default values, and then click Next to
go to the Data Policy page.
- Select Create a new policy and then select Balance
security and performance.
- Click Next to go to the Applicable
Interfaces page.
- Select TRLINE from the Line table.
- Click Next to go to the Summary page.
- Review the objects that the wizard will create to ensure they are
correct.
- Click Finish to complete the configuration.
- When the Activate Policy Filters dialog
box appears, select Yes, activate the generated policy
filters then select Permit all other traffic.
- Click OK to complete the configuration.