Update access control policy in Firewall Threat Defense device

Before deploying a remote access VPN policy, update the access control policies on the devices with rules that permit all traffic from the outside interface, with the client networks as the source and the corporate network as the destination.

Note

If you enable the Bypass Access Control policy for decrypted traffic (sysopt permit-VPN) option when configuring the remote access VPN policy, you do not have to update the access control policy.

Enable or disable the option for all your VPN connections. If you disable this option, ensure that the VPN traffic is allowed by the access control policy or pre-filter policy.

Before you begin

Configure remote access VPN policies using the Remote Access VPN Policy Wizard.

Procedure


Step 1

Choose Policies > Security policies > Access Control.

Step 2

Click the edit icon next to the access control policy that you want to update and click Add Rule.

Step 3

In the Name field, enter the name for the rule.

Step 4

Click the Enable Rule toggle button.

Step 5

From the Action drop-down list, choose Allow or Trust.

Step 6

Click the Zones tab.

  1. Select the outside zone from the available zones and click Add Source Zone.

  2. Select the inside zone from the available zones and click Add Destination Zone.

Step 7

Click the Networks tab.

  1. Select the inside network, including the inside interface of the device and the corporate network, from the available networks and click Add Destination Network.

  2. Select the VPN IP address pool network (client network) from Available Networks and click Add Source Network.

Step 8

Configure other required access control rule settings and click Apply and Add New Rule.

Step 9

Save the rule and access control policy.