Creating the IPsec policy

  1. Go to Configuration > VPN > IPsec VPN > Encryption Policy - Tunnels tab.
  2. Select the IPsec policy you want to change. In this example: IPsec 01.
  3. Click the Mobile Client tab.

Config mode mobile policy

  1. Click Add and select Mobile client in config mode.
    A configuration wizard will start.
  2. In the Local resources field, select the all object.
    IMPORTANT
    You must select the all object, not the resources accessible to mobile users through the IPsec VPN tunnel. This is due to the default operation in full-tunneling mode.
  3. In the Peer selection field, choose the mobile profile created previously. In this example: mobile_IKEv2_EAPTLS.
  4. In the Remote networks field, select the network object created in the Define a network object containing the IP addresses assigned to mobile peers step. In this example: IKEv2_EAPTLS_Clients_Network.
  5. Click on Finish.
  6. Double-click on the Status column to enable the rule.
  7. Click on Apply, then on Save to confirm and enable this configuration.
  8. Click on Yes, activate the policy.

The IPsec policy configured in Config mode is therefore: