Adding security policies
- To add an address for the local network, go to Policy & Objects > Addresses.
- Set Type to Subnet, Subnet/IP Range to the local subnet, and Interface to lan.
- To create a security policy allowing access to the internal network through the VPN tunnel interface, go to Policy & Objects > IPv4 Policy.
- Set Incoming Interface to ssl.root and Outgoing Interface to lan. Select Source and set Address to all and User to the Employee user group. Set Destination to the local network address, Service to ALL, and enable NAT.
- Add a second security policy allowing SSL VPN access to the Internet.
- For this policy, set Incoming Interface to ssl.root and Outgoing Interface to wan1. Select Source and set Address to all and User to the Employee user group.
If you are allowing split tunneling, this policy is not required. |