Creating a VPN Site

Configure and create a VPN site by defining remote site settings, encryption parameters, and advanced VPN options.

Creating a VPN Site

  1. Go to the VPN tab.
  2. Select VPN Sites.

  3. Create a new VPN site.
  4. On the Remote Site tab:
    • In the Site name field, enter a name for the VPN site. For example, SASE.

    • From the Connection type list, select Host name or IP address.

    • In the IP address field, enter the IP address of the SASE site.

    • In the Authentication section, select Pre-shared secret and enter the same secret Password as in SASE.

  5. In the Remote Site Encryption Domain section, select Encrypt according to routing table.

  6. Go to the Encryption tab and configure parameters according to the SASE encryption parameters.

  7. Go to the Advanced tab and configure these parameters:
    • Clear the Enable Permanent VPN tunnels checkbox.

    • Clear the Remote getaway is a Check Point Security Gateway checkbox.

  8. In the second part of the Advanced tab, in the Encryption Method section, select IKEv2.
  9. Select the option to configure the identities.
  10. In the Peer ID field, enter the VPN site name. The Peer ID must match the VPN site name and the VTI peer name. In this example, enter SASE.
  11. In the Gateway ID field, keep the global identifier generated when you create the VPN site on the Spark appliance.