VPN > Settings
897
SonicOS 5.8.1 Administrator Guide
Step 5 Click the Network tab.
Step 6 Select a local network from Choose local network from list if a specific local network can
access the VPN tunnel. If traffic can originate from any local network, select Any Address. Use
this option is a peer has Use this VPN Tunnel as default route for all Internet traffic
selected. You can only configure one SA to use this setting. Alternatively, select Choose
Destination network from list, and select the address object or group.
Step 7 Click on the Proposals tab.
Step 8 Define an Incoming SPI and an Outgoing SPI. The SPIs are hexadecimal
(0123456789abcedf) and can range from 3 to 8 characters in length.
Caution Each Security Association must have unique SPIs; no two Security Associations can share
the same SPIs. However, each Security Association Incoming SPI can be the same as the
Outgoing SPI.
Step 9 The default values for Protocol, Phase 2 Encryption, and Phase 2 Authentication are
acceptable for most VPN SA configurations.