Configuring the VPN Tunnel Server

You use the System > Network > VPN tunneling page to configure VPN tunnel server options.

Specifying IP Filters

The VPN Tunneling Server uses the filter list to assign IP addresses to clients requesting a VPN client session. A filter is an IP address/netmask combination. For example: 10.11.0.0/255.255.0.0 or 10.11.0.0/16.

To add an IP address to the VPN tunneling filter list:

1.In the admin console, choose System > Network > VPN tunneling.

2.Specify an IP address/netmask combination and then click Add.

Specifying the VPN Tunneling Server Base IP Address

Only change the VPN tunneling server base IP address when instructed to do so by the Ivanti Support team.

To change the VPN tunneling server base IP address:

1.In the admin console, choose System > Network > VPN tunneling.

2.In the VPN Tunnel Server IP Address text box, specify the base IP address used by the VPN tunneling server to assign IP addresses to the tunnel interfaces created for VPN Tunneling sessions. If your service is deployed in a cluster, the base IP address you specify will be common to all cluster nodes. Be sure to configure a base IP address that does not encroach on the IP address pool for VPN Tunneling Connection Profiles or for or the IP addresses for the external or internal interface. Take DHCP servers into consideration.

For IPv6 addresses, no additional configuration is required. The base IPv6 address used by the VPN tunneling server will be generated by prepending the network prefix fd00:: to IPv4 address configured for this.

3.Save the configuration.