Defining a network object that contains IP addresses assigned to mobile peers

The network assigned to clients must not already be known to the firewall.

To do this, it must not be:

  • A directly connected network,
  • A network known through routing,
  • A network involved in the configuration of another IPsec tunnel.

In Configuration > Objects > Network:

  1. Click on Add.
  2. Select Network.
  3. Enter a Name for this object. In this example: IKEv2_EAPTLS_Clients_Network.
  4. Enter the Network IP address field in the form of a network/mask.
    This network must contain at least as many IP addresses as users likely to connect simultaneously to the IPsec VPN tunnel.
    Examples:
    192.168.9.0/24 or 192.168.9.0/255.255.255.0: 256 addresses therefore 256 .
    192.168.9.0/24 or 192.168.9.0/255.255.255.0: 512 addresses, therefore 512 .
  5. Click on Create.