Allowing IPsec VPN access in filter policies
The traffic that is required in order to set up the IPsec VPN is managed by an implicit filter rule. The filter policy will therefore manage how mobile users who were authenticated via the VPN access internal resources.
In the module Configuration > Security policy > Filter - NAT > Filtering tab:
- In the filter policy, select the row below the one in which you wish to add the rule allowing mobile users to use the IPsec VPN.
- Click on New rule.
- Select Single rule.
A new row appears. - In the newly added row, double-click on the cell in the Action column.
The configuration window of the rule opens. - In the Action field, select pass.
- In the menu on the left side of this window, select Source.
- In the User field, select the group of users allowed to set up IPsec VPN tunnels (EAP-GTC-CERT Users@stormshield.eu in this example).
- Click on the Advanced properties tab in the Source section.
- For the Via field, select IPsec VPN tunnel.
- For the Authentication method field, select IPsec VPN.
- In the menu on the left side of this window, select Destination.
- Click on Add in the Destination hosts grid.
- Select the network that mobile users can access through the IPsec VPN tunnel (group IKEv2_EAP_LOCAL_NET_GRP in the example).
- In the menu on the left side of this window, select Inspection.
- In the Inspection profile field, select the IPS profile that contains the TCP-UDP profile with the MSS option (IPS_03 in the example).
- Click on OK.
- Double-click on the cell corresponding to the Status column to enable this rule.
Its status will switch to ON. - Click on Apply, then on Yes, activate the policy.
The filter rule configured is therefore: