General Information on Tunnels

A Tunnel is a mechanism provided by the Firewall that allows secure communications between secure networks over an nonsecure intervening network like the Internet. It constructs a virtual private network (VPN) between two different sites providing authentication and encryption. When you create a tunnel, a complete IP packet, including its header information, is encapsulated in a new IP packet only seen by the source and destination hosts. The original IP packet is protected during the transmission between hosts, according to user specified policy.

Further Information

Creating a Virtual Private Network
Example of Virtual Private Networks

Tunnel List

The list shows the current values used by the Firewall for this function. To select, click on the row desired and then select an action by clicking a button on the right.

Icon Key

Create new
Activated tunnel
Deactivated tunnel

Open

After selecting an item on the list, press the "Open" button to view or modify that item. To add a new item, select "NEW" item on the list and press "Open".

Copy

The "Copy" button helps save time when adding new items to the list. After selecting an item on the list, press the "Copy" button to create an item that is similar to the selected item. Pressing the "Copy" button will open a new item that will copy field values from the item that was selected on the list. You will then be able to modify field values as needed for the new item.

Delete

Press the "Delete" button to delete a selected item from the list.

Import

As a tunnel partner, you will receive tunnel context definitions that have been exported to you. When you receive these tunnel context definitions from a tunnel partner, you will place these files in a directory of your choice. Select Import, then enter the name of the directory where you have restored the files you have imported from your tunnel partner.

Export

As a tunnel owner, after you have defined a set of tunnel context definitions, you will want to export one or more of these definitions to a tunnel partner. Select the tunnel Id(s) you want to export and then Click "Export". You can then enter a directory name in the entry field. The directory name is an arbitrary name that you have to create first; it does not have to match anything and this is where the tunnel information is temporarily placed for export to a partner. After you have completed this Export operation, the directory contains the names of the files that need to be moved to your tunnel partner's machine.

Activate (Tunnels)

Select from the list and click "Activate" to activate a tunnel.

Deactivate (Tunnels)

Select from the list and click "Deactivate" to deactivate a tunnel.

Shutdown

Select Shutdown only if you want to stop all tunnel activity for an extended period of time. Or use shutdown for security reasons if you need to stop all tunnel activity immediately. Be aware that if you have multiple tunnel partners, shutdown causes a restart with each of those partners.

Close

Press the "Close" button to eliminate the window from your display.

Refresh

Click "Refresh" to re-access the data from the Firewall and re-display the data on this panel.