VPN > Settings
567
SonicOS Enhanced 4.0 Administrator Guide
–
If you selected IKEv2 in the Proposals tab:
• Select Enable Keep Alive to use heartbeat messages between peers on this VPN tunnel. If one
end of the tunnel fails, using Keepalives will allow for the automatic renegotiation of the tunnel
once both sides become available again without having to wait for the proposed Life Time to
expire.
• Select Suppress automatic Access Rules creation for VPN Policy to turn off the automatic
access rules created between the LAN and VPN zones for this VPN policy.
• Select Enable Windows Networking (NetBIOS) Broadcast to allow access to remote network
resources by browsing the Windows® Network Neighborhood.
• Select Enable Multicast to allow IP multicasting traffic, such as streaming audio (including
VoIP) and video applications, to pass through the VPN tunnel.
• Select Apply NAT Policies if you want the SonicWALL to translate the Local, Remote or both
networks communicating via this VPN tunnel. To perform Network Address Translation on the
Local Network, select or create an Address Object in the Translated Local Network menu. To
translate the Remote Network, select or create an Address Object in the Translated Remote
Network menu. Generally, if NAT is required on a tunnel, either Local or Remote should be
translated, but not both. Apply NAT Policies is particularly useful in cases where both sides of
a tunnel use either the same or overlapping subnets.
• To manage the local SonicWALL through the VPN tunnel, select HTTP, HTTPS, or both from
Management via this SA. Select HTTP, HTTPS, or both in the User login via this SA to allow
users to login using the SA.
• Enter the Default LAN Gateway if you have more than one gateway and you want this one
always to be used first.
• Select an interface or Zone from the VPN Policy bound to menu. A Zone WAN is the preferred
selection if you are using WAN Load Balancing and you wish to allow the VPN to use either
WAN interface.
• Under IKEv2 Settings (visible only if you selected IKEv2 for Exchange on the Proposals tab),
The Do not send trigger packet during IKE SA negotiation checkbox is cleared by default
and should only be selected when required for interoperability.