33
C-2.2 Build 2 Filter Lists: “WinXP Broadband VPN Router” and “Broadband VPN Router WinXP”.
[Filter List 1] WinXP Broadband VPN Router
1. In the to_VPNRouter Properties, deselect the Use Add Wizard check box, and then click Add button to create a new rule.
2. From the IP Filter List tab, click the Add button.
3. Type an appropriate name “XP Broadband VPN Router” for the filter list, deselect the Use Add Wizard check box, and then click Add button.
4. In the Source address area, click My IP Address.
5. In the Destination address field, select A specific IP Subnet, and fill in the IP Address “192.168.1.0” and Subnet mask “255.255.255.0”.
6. If you want to type a description for your filter, click the Description tab.
7. Click OK button. Then click OK (for WinXP) or Close (for Win2000) button on the IP Filter List Window.
[Filter List 2] Broadband VPN Router WinXP
8. On the IP Filter List tab, click the Add button.
9. Type an appropriate name “Broadband VPN Router XP” for the filter list, click to clear the Use Add Wizard check box, and then click Add.
10. In the Source address area, click A specific IP Subnet, and fill in the IP Address “192.168.1.0” and Subnet mask “255.255.255.0”.
11. In the Destination address area, click My IP Address.
12. If you want to type a description for your filter, click the Description tab.
13. Click OK, and then click OK.
C-2.3 Configure Individual Rule of 2 Tunnels
[Tunnel 1] WinXP Broadband VPN Router
1. From the IP Filter List tab, click the filter list “XP Broadband VPN Router”.
2. From the Filter Action tab, click the filter action “Require Security”, and click the Edit button.
3. Check that the Negotiate security option is enabled, and deselect the Accept unsecured communication, but always respond using IPsec check box.
4. Select the Session key Perfect Forward Secrecy (PFS) and remember to check the PFS option on the Broadband VPN Router, and then click the OK button.
5. From the Authentication Methods tab, click the Edit button.
6. Change the authentication method to “Use this string (preshared key)”, enter the string “Test”, and then click the OK button. This new Preshared key will be
displayed in Authentication method preference order. Click the OK button to continue.
7. From the Tunnel Setting tab, click The Tunnel endpoint is specified by this IP Address box, and then type the WAN IP Address “140.111.1.1 ”(Note: ISP
provided IP Address; this is only an example.) of Broadband VPN Router.
8. From the Connection Type tab, select All network connections, and then click the OK or Close button to finish this rule.
[Tunnel 2] Broadband VPN Router WinXP
9. In the to_VPNRouter Properties, deselect the Use Add Wizard check box, and then click the Add button to create the second IP Filter.
10. On the IP Filter List tab, click the filter list “Broadband VPN Router XP”.
11. From the Filter Action tab, click the filter action “Require Security”.
12. From the Authentication Methods tab, click the Edit button.
13. Change the authentication method to “Use this string (preshared key)”, enter the string “Test”, and then click the OK button. This new Preshared key will be
displayed in Authentication method preference order. Click the OK button to continue.
14. From the Tunnel Setting tab, click The Tunnel endpoint is specified by this IP Address box, and then type the Windows 2000/XP IP Address
“140.111.1.2”.
15. From the Connection Type tab, select All network connections, and then click the OK(for WinXP) or Close(for Win2000) button to finish.
16. From the Rules tab, click the OK button to back to the secpol screen.
C-2.4 Assign New IPsec Policy
1. In the IP Security Policies on Local Computer MMC snap-in, right-click policy named “to_VPNRouter”, and then click Assign. A green arrow appears in the
folder icon.
ENGLISH