Configuring the
Windows 2000 Computer using the IPSec policy is configured in the MMC.
To start the IPSec
Policy, Start >Run
>secpol.msc.
Right click on IP Security
Policy on Local Machine and choose Create IP Security Policy (Figure).
Go through the IP Security
Policy Wizard. Click Next and type Policy Name, ms-mvps in our
case. Click Next.
Deselect Active to default
response rule. Click Next. Leave Edit Policy checked.
Click Finish.
Click Add, type a descriptive name for the
IP Filter list such as Home to Office and click Add.
Choose A specific IP address as source
address and enter the Windows 2000 IP address, 10.0.0.11 as IP Address and
255.255.255.255 as subnet mask. Choose A specific IP Subnet
as Destination address and enter the Office LAN IP address and subnet
mask, 192.168.0.0 and 255.255.255.0.. Uncheck the box for Mirrored (Figure).
Click OK, then Close.
Click Filter Action >Add.
Click General and enter a name for the
Filter Action.
Security Methods. Check Negotiate security.
Leave all the check boxes unchecked. Click Edit (Figure).
Choose Custom and click setting. Check
ESP and choose MD5 and 3DES for integrity and
encryption algorithm. Check the box for Generate a new key every
and enter 3600 seconds. Click OK until you are back to Edit
Rule Properties.
Click Tunnel Setting and enter the WAN IP
address of the NETGEAR router, 172.16.0.1 as “The tunnel dendpoint is
specified by this IP Address” (Figure).
Click Authentication Methods and click
Edit. Click Use this string to protect the key exchange (Preshared
key) and enter the preshared key. Click OK and then
Close to get back to the security policy window. This finishes to
create room Home to Office rule.
Now, you need to create the Office to Home rule.
The main difference between Office to Home and Home to Office are Tunnel Setting
and A specific IP address. Many people are confused withThe
tunnel dendpoint is
specified by this IP Address of the Tunnel Setting. Check this page
for the details, The difference of IPSec Tunnel
Setting between local to remote and remote to local.