Directional VPN Enforcement

Overview of Directional VPN

When a VPN community is selected in the VPN column of the Security PolicyClosed Collection of rules that control network traffic and enforce organization guidelines for data protection and access to resources with packet inspection. Rule BaseClosed All rules configured in a given Security Policy. Synonym: Rulebase., the source and destination IP addresses can belong to any of the Security Gateways in the community. In other words, the traffic is bidirectional; any of the Security Gateways can be the source of a connection, any of the Security Gateways can be the destination endpoint. But what if the administrator (in line with the company's security policy) wished to enforce traffic in one direction only? Or to allow encrypted traffic to or from Security Gateways not included in the VPN community? To enable enforcement within VPN communities, VPN implements Directional VPN.

Directional VPN specifies where the source address must be, and where the destination address must be. In this way, enforcement can take place:

Directional Enforcement within a Community

Configurable Objects in a Direction

Directional Enforcement Between VPN Communities

Configuring Directional VPN Within a VPN Community

Configuring Directional VPN Between VPN Communities