0% found this document useful (0 votes)
63 views212 pages

LNT Prerequisite Master Template v1.1

Uploaded by

Raj Khanna
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as XLSX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
63 views212 pages

LNT Prerequisite Master Template v1.1

Uploaded by

Raj Khanna
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as XLSX, PDF, TXT or read online on Scribd
You are on page 1/ 212

Sr. No.

Parameter

1 Location

2 Local Contact Person

3 Device Model
4 Network Architecture
5 OS Version
6 Management IP and mask
7 Hostname
8 DNS Server IP
9 NTP Server IP

10 Interface Configuration

11 Interface IP / Network

12 Zone Name & Mapping


13 HA Mode
IPSec Tunnel Details
14
(Provide filled VPN Template)
15 Virtual router Name
Routing Protocol (Static/Dynamic)
16
Static Routes details
17 Address Object/Service Object details
Security/Access Policy details
18
NAT Policy details
Remote Logging and Remote Management /
19
Authentication details

Global Protect parameters and AD


20
Integration for EAIC DC

Interface Details
Interface Interface Type
ethernet1/1 Layer3
ethernet1/2 Layer3
ethernet1/3 Layer3
ethernet1/4
ethernet1/5 Layer3
ethernet1/6
ethernet1/7
ethernet1/8
ethernet1/9
ethernet1/10
ethernet1/11
ethernet1/12
ethernet1/13
ethernet1/14
ethernet1/15
ethernet1/16
ethernet1/17 Layer3
ethernet1/18 Aggregate (ae1)
ethernet1/19 Layer3
ethernet1/20
ae1 Layer3

Zone Details

Name Type
DC-Core layer3
DC_Airtel layer3
DC_Vodafone layer3
OfficeLan layer3
VPN layer3

Address Object Details

SR Name
1 172.18.100.27
2 api.irisgst.com
3 EBG_Web
4 EBG_Web_Ext
5 H_125.18.115.26
6 H_125.18.115.69
7 H_125.18.115.76
8 H_172.18.100.100
9 H_172.18.100.110
10 H_172.18.100.120
11 H_172.18.100.20
12 H_172.18.100.25
13 H_172.18.100.30
14 H_172.18.100.40
15 H_172.18.100.50
16 H_172.18.100.60
17 H_172.18.100.80
18 H_172.18.100.85
19 H_172.18.100.90
20 H_172.18.102.90
21 H_172.18.102.91
22 H_172.18.105.10
23 H_172.18.105.20
24 H_172.18.107.143
25 H_172.18.107.220
26 H_172.18.109.90
27 IP_118.185.53.118
28 IP_118.185.53.186
29 IP_122.15.220.178
30 IP_123.63.115.119
31 IP_123.63.205.13
32 IP_125.18.115.119
33 IP_172.18.104.133
34 IP_172.18.96.110
35 IP_59.164.64.154
36 IP_59.164.64.156
37 IP_Range-172.18.105.31-36
38 IP_Range-172.18.105.46-48
39 N172.18.95.0m24
40 N_172.18.96.0m20
41 R_172.18.201.51-70
42 SAP_WebDispatcher
43 VodaforneOutboundNAT

Address Group details

SR Name
1 EBG_Outbound_125.18.115.101

Service Object details

Sr. Name
1 ftp_989
2 ftp_990
3 service-http
4 service-https
5 tcp-465
6 TCP-53
7 TCP44301-44305
8 tcp_1433
9 tcp_22
10 TCP_22
11 tcp_25
12 tcp_3000
13 tcp_443
14 tcp_44301-44303
15 TCP_44303
16 tcp_45--
17 tcp_4500
18 tcp_8010
19 tcp_8020
20 tcp_8030
21 tcp_8031
22 tcp_8040
23 tcp_8050
24 tcp_8060
25 tcp_8070
26 tcp_8080
27 TCP_8089
28 tcp_8090
29 tcp_8400
30 tcp_8401
31 tcp_8403
32 tcp_8443
33 tcp_9251
34 UDP-53

VPN Tunnel Interface Details

Sr Interface
1 tunnel
2 tunnel.1
3 tunnel.2
4 tunnel.3
5 tunnel.4
6 tunnel.5
7 tunnel.6
8 tunnel.7
9 tunnel.8
10 tunnel.9
11 tunnel.10
12 tunnel.11
13 tunnel.12
14 tunnel.13

VPN IKE Gateway details

Sr Name
1 TAMCO
2 Jebel_Ali
3 Indonesia
4 Saudi
5 LT_Tamco
6 EA_SITEL
7 Powai_Office
8 Tamco_Malaysia_Subang
9 Mahape_IPSEC
10 Nagpur_IKE_Gw
11 Powai_Office_Airtel_JIO
12 Nagpur_IKE_GW_2

IKE Crypto details

Sr Name
1 default
2 Suite-B-GCM-128
3 Suite-B-GCM-256
4 TAMCO_IKE
5 Jebel_IKE
6 Indonesia_IKE
7 Saudi
8 LT_Tamco
9 LT_Tamcomalaysia_subang
10 EA_SITEL
11 PowaiOffice
12 Mahape
13 Nagpur_IKE_Crypto

IPSEC Crypto details

Sr Name
1 default
2 Suite-B-GCM-128
3 Suite-B-GCM-256
4 TAMCO_2013_IPSEC
5 Jebel_Ali_IPSEC
6 Indonesia_IPSEC
7 Saudi_IPSEC
8 LT_Tamco_IPSEC
9 LT_Tamco_Malaysia_subang
10 EA_IPSEC
11 PowaiOffice
12 Mahape_IPSEC
13 Nagpur_IPSEC_Crypto

IPSEC Tunnels Details


Sr Name
1 EA_SITEL
2 Indonesia_VPN
3 Jebel_Ali
4 LT_Tamco_mesh
5 LT_Tamcomalaysia_Subang
6 Mahape_IPSEC
7 Nagpur_IPSEC_Tunnel
8 Nagpur_IPSec_Tunnel_2
9 Powai_Office
10 Powai_Office_Airtel_JIO
11 Saudi
12 TAMCO_New_2013

Security Policies

Sr. Name
1 Checkpoint Management from Mahape
2 Checkpoint Management from Mahape-1
3 Inbound_Access_Policy
4 Inbound_Access_Policy-ESPQMA
5 Temp_Internet_Access
6 Temp_Internet_api.irisgst.com
7 Proxy_Internet_Access
8 SMTP
9 EAIC_WebDispatcher
10 FTPs
11 adselfservice
12 Portalend_Prod
13 Portalend_UAT
14 ftp.lteaglobal.com
15 ftp.lteaglobal.com-1
16 SAP_WebDispatcher
17 SPED-WEB-SERVER
18 portal.lteaglobal.com
19 InternetAccess
20 InternetAccess-Port 8089
21 PING
22 ADFS
23 OfficeToCore
24 CoreToOffice
25 eaicwebdisps
26 [Disabled] Firewall Access
27 Bizwhizadmin
28 intrazone-default
29 interzone-default
NAT Rules

Sr Name
1 [Disabled] Checkpoint Management Outbound-1
2 Test
3 IBM_Ser_SAP_HANA_Outbound
4 Checkpoint Management Outbound
5 [Disabled] VPN_NAT-1
6 [Disabled] VPN_NAT
7 SMTP_Vod_NAT
8 SMTP_Outbound
9 JBOSSQAT
10 JBOSSQAT-Airtel
11 SMTP_inbound
12 [Disabled] 3232CoreTempNat
13 [Disabled] Indonesisa_VPN
14 Airte
15 Airtel_SolmanPRD
16 Airtel_FTP_NAT
17 lteasmprldev
18 SAPEportalServer
19 Sapphirehelpdesk
20 SCADA
21 lteainmprmap
22 JBOSSProd
23 InternalNAT
24 MobileApplication
25 eaafsspprd
26 eaafsspdev
27 SCMportalserverQuality
28 SAPEportalserver
29 XAMPPRD
30 lteaspedwa3prd
31 ManageengineADSS
32 Airtel_ManageengineADSS-1
33 INMPRMAP
34 INMPRMAP-Airtel
35 INMPRMAP_outbound
36 OldSPPrd
37 airtel_sharepoint
38 SharepointProd
39 SharepointProd_outbound_Airtel
40 eamomtidev
41 IRM
42 JBOSSDev
43 Vod_lteamaahprd
44 Vod_FTP
45 Vod_lteawsftpprd
46 Vod_lteasmprldev
47 Vod_eaappstore
48 Vod_eaafariaprd
49 Vod_eaafrlprd
50 Vod_eaafrldev
51 SAP_WebDispatcher
52 Vod_MobileApplication
53 Vod_MobienServer
54 Vod_MobienServer-1
55 Vod_InternetServer
56 Airtel_lntebg
57 Airtel_lntebg-Outbound
58 Vod_JBOSSProd
59 Vod_C_ASMP
60 Airtel_C_ASMP
61 Vod_C_ASMD
62 Airtel_C_ASMD
63 Vod_C_ASMTQAT
64 SAP_SAHYOG_172.18.106.72
65 Outbound_NAT_EBG1
66 Outbound_NAT_EBG2
67 Outbound_NAT_EBG3
68 Outbound_NAT_EBG4
69 Outbound_NAT_EBG5
70 Outbound_NAT_Temp_Internet
71 Outbound_NAT_EBG_Vod2
72 Outbound_NAT_EBG_Vod2-1
73 Outbound_NAT_EBG_Vod4
74 Outbound_NAT_EBG_Vod5
75 Outbound_NAT_EBG_Vod6
76 Outbound_NAT_EBG_Vod7
77 Outbound_NAT_EBG_Vod8
78 Outbound_NAT_EBG_Vod1
79 Ofc_FW_NAT
80 VodafoneInternet
81 AirtelInternet
82 [Disabled] Checkpoint Management from Mahape
83 Checkpoint Management from Mahape-1
84 lteaspedwa3prd_Inbound
85 ESP_QA_Quality_Inspector
86 XAMPRD_Airtel_Inbound
87 Airtel_MobienServer
88 Automation4me_CA_Airtel
89 Seclore_Server_Airtel
90 JBOSS_Dev_Airtel
91 Sharepoint_Airtel
92 SAP_mobility_125.18.115.112
93 SAP_mobility_125.18.115.115
94 SAP_mobility_125.18.115.116
95 SAP_router_125.18.115.117
96 SAP_mobility_125.18.115.114
97 SAP_mobility_125.18.115.113
98 Web_Server_Temp_NAT
99 McAfee_Agent_Handler
100 SAP_WebDispatcher_Airtel
101 Sharepoint_Dev_Airtel
102 [Disabled] Temp Firewall access

Static Routes Details

Name Destination IP
172.18.31.0m24 172.18.31.0/24
172.18.32.0m24 172.18.32.0/24
172.18.33.0m24 172.18.33.0/24
172.18.40.0m24 172.18.40.0/24
172.18.41.0m24 172.18.41.0/24
172.18.42.0m24 172.18.42.0/24
172.18.43.0m24 172.18.43.0/24
172.18.44.0m24 172.18.44.0/24
172.18.140.0m24 172.18.140.0/24
172.18.141.0m24 172.18.141.0/24
172.18.142.0m24 172.18.142.0/24
172.18.143.0m24 172.18.143.0/24
172.18.144.0m24 172.18.144.0/24
172.18.70.0m24 172.18.70.0/24
172.18.71.0m24 172.18.71.0/24
172.18.72.0m24 172.18.72.0/24
172.18.73.0m24 172.18.73.0/24
172.18.74.0m24 172.18.74.0/24
VLAN95 172.18.95.0/24
VLAN96 172.18.96.0/20
CoreLAN 172.16.0.0/12
172.18.34.0m24 172.18.34.0/24
10.0.0.0m8 10.0.0.0/8
10.2.1.200 10.2.1.200/32
VLAN30 172.18.30.0/24
GuestWIFI 172.18.200.0/24
1.1.1.1 1.1.1.1/32
172.18.201.0m24 172.18.201.0/24
192.168.0.0m16 192.168.0.0/16
GP_VPN_Subnet 192.168.255.0/24
TAMPCO_10.7.160.0m24 10.7.160.0/24
TAMPCO_10.7.182.0m24 10.7.182.0/24
TAMPCO_10.7.176.0m21 10.7.176.0/21
10.0.0.0jli23 10.0.0.0/23
10.20.135.0m24 10.20.135.0/24
10.20.138.0Sau 10.20.138.0/24
Subang malaysia10.9.253 10.9.253.0/24
Tamco2013 malaysia10.9.192 10.9.192.0/24
EAsitelmumbai1 10.34.128.0/18
EAsitelmumbai2 10.34.192.0/18
EAsitelmumbai3 10.127.0.0/16
EAsitelmumbai4 10.138.0.0/19
EAsitelmumbai5 10.138.128.0/19
EAsitelmumbai6 10.223.33.0/24
EAsitelmumbai7 10.233.3.0/24
Details

EAIC DC
Schneider Electric India Pvt. Ltd. TC-II, B Tower 3rd
Floor, Saki Vihar Road, Powai, Mumbai 400 072

Arvind Rao
98203 77653 [email protected]
PA5250 + PA5250 HA

9.1.5

1/1 - Primary Internet


1/2 - LAN
1/3 - DMZ (reserved)
1/4 - DMZ (reserved)
1/5 - Secondary Internet (if any)
WAN -
LAN -
DMZ -
HA1 192.168.5.0/24 (split into /30 ) as per image
HA2 -
Provide Zone in below Template
Active-Passive
Count -
Spoke Locations -
Default-VR
Static
Provide Static Route in below Template
As per Security Policy in below Template
Provide Security Policy in below Template
Provide Security Policy in below Template
Local Authentication and logging

VPN Subnet -
Access to VPN Subnet (Security Policies) -
Compliance Requirement for Endpoints -
User/Group details (as per Active Directory) -
Authentication and Authorization details
Details of LDAP Server -
Service account details -
Management Profile Link State
PING Link Speed: 1000 Mbps;Link Duplex: full;ethernet1/1: configured and up
PING Link Speed: 1000 Mbps;Link Duplex: full;ethernet1/2: configured and up
PING Link Speed: 1000 Mbps;Link Duplex: full;ethernet1/3: configured but down
Link Speed: 1000 Mbps;Link Duplex: full;ethernet1/4: not configured and down
Link Speed: 1000 Mbps;Link Duplex: full;ethernet1/5: configured but down
Link Speed: 1000 Mbps;Link Duplex: full;ethernet1/6: not configured and down
Link Speed: 1000 Mbps;Link Duplex: full;ethernet1/7: not configured and down
Link Speed: 1000 Mbps;Link Duplex: full;ethernet1/8: not configured and down
Link Speed: 1000 Mbps;Link Duplex: full;ethernet1/9: not configured and down
Link Speed: 1000 Mbps;Link Duplex: full;ethernet1/10: not configured and down
Link Speed: 1000 Mbps;Link Duplex: full;ethernet1/11: not configured and down
Link Speed: 1000 Mbps;Link Duplex: full;ethernet1/12: not configured and down
Link Speed: 1000 Mbps;Link Duplex: full;ethernet1/13: not configured and down
Link Speed: 1000 Mbps;Link Duplex: full;ethernet1/14: not configured and down
Link Speed: 1000 Mbps;Link Duplex: full;ethernet1/15: not configured and down
Link Speed: 1000 Mbps;Link Duplex: full;ethernet1/16: not configured and down
PING_HTTPS_SSH Link Speed: 10000 Mbps;Link Duplex: full;ethernet1/17: configured and up
Link Speed: 10000 Mbps;Link Duplex: full;ethernet1/18: configured but down
PING_HTTPS_SSHLink Speed: 10000 Mbps;Link Duplex: full;ethernet1/19: configured but down
Link Speed: 10000 Mbps;Link Duplex: full;ethernet1/20: not configured and down
;Mode: Passive;Local Key: 16;Local PING
MAC: 84:d4:12:c7:64:01;Local Priority: 32768;Partner Key: 0;Partner MAC: 00:00:00:00:00:00;Partn

Interfaces / Virtual Systems Zone Protection Profile


ethernet1/17;ethernet1/3 InternalZoneProtec
ethernet1/2 AirtelZonePP
ethernet1/1 VodafoneInternetZoneProtection
ethernet1/19 InternalZoneProtec
tunnel.3;tunnel.4;tunnel.5;tunnel.6;tunnel.7;tunnel.8;tunnel.9;tunnel.11;tunnel.12;tunnel.13

Type Address
IP Netmask 172.18.100.27
FQDN api.irisgst.com
IP Netmask 172.18.107.30
IP Netmask 123.63.115.103
IP Netmask 125.18.115.26
IP Netmask 125.18.115.69
IP Netmask 125.18.115.76
IP Netmask 172.18.100.100
IP Netmask 172.18.100.110
IP Netmask 172.18.100.120
IP Netmask 172.18.100.20
IP Netmask 172.18.100.25
IP Netmask 172.18.100.30
IP Netmask 172.18.100.40
IP Netmask 172.18.100.50
IP Netmask 172.18.100.60
IP Netmask 172.18.100.80
IP Netmask 172.18.100.85
IP Netmask 172.18.100.90
IP Netmask 172.18.102.90
IP Netmask 172.18.102.91
IP Netmask 172.18.105.10
IP Netmask 172.18.105.10
IP Netmask 172.18.107.143
IP Netmask 172.18.107.220
IP Netmask 172.18.109.90
IP Netmask 118.185.53.118
IP Netmask 118.185.53.186
IP Netmask 122.15.220.178
IP Netmask 123.63.115.119
IP Netmask 123.63.205.13
IP Netmask 125.18.115.119
IP Netmask 172.18.104.133
IP Netmask 172.18.96.110
IP Netmask 59.164.64.154
IP Netmask 59.164.64.156
IP Range 172.18.105.31-172.18.105.36
IP Range 172.18.105.46-172.18.105.48
IP Netmask 172.18.95.0/24
IP Netmask 172.18.96.0/20
IP Range 172.18.201.51-172.18.201.70
IP Netmask 172.18.105.251
IP Range 172.18.200.100-172.18.200.200

Addresses
R_172.18.201.51-70

Protocol Destination Port


TCP 989
TCP 990
TCP 808,080
TCP 443
TCP 465
TCP 53
TCP 44301-44305
TCP 1433
TCP 22
TCP 22
TCP 25
TCP 3000
TCP 443
TCP 44301-44303
TCP 44303
TCP 4500
TCP 4500
TCP 8010
TCP 8020
TCP 8030
TCP 8031
TCP 8040
TCP 8050
TCP 8060
TCP 8070
TCP 8080
TCP 8089
TCP 8090
TCP 8400
TCP 8401
TCP 8403
TCP 8443
TCP 9251
UDP 53

Management Profile IP Address


none
PING none
none
none
none
none
none
none
none
none
none
none
none
none

Peer Address Local Address Interface


121.122.44.206 ethernet1/2
151.253.7.202 ethernet1/2
180.250.57.114 ethernet1/2
212.107.103.90 ethernet1/2
27.131.52.2 ethernet1/2
115.112.41.196 ethernet1/2
123.63.229.241 ethernet1/1
1.32.62.98 ethernet1/2
59.164.64.153 ethernet1/2
103.132.207.62 ethernet1/2
136.232.254.90 ethernet1/2
103.132.204.14 ethernet1/1

Encryption Authentication
aes-128-cbc, 3des sha1
aes-128-cbc sha256
aes-256-cbc sha384
aes-256-cbc sha256
aes-256-cbc md5
aes-256-cbc sha256
3des md5
aes-256-cbc sha256
aes-256-cbc sha256
3des sha1
aes-128-cbc sha256
aes-256-cbc sha1
aes-128-cbc sha1

ESP/AH Encryption
ESP aes-128-cbc, 3des
ESP aes-128-gcm
ESP aes-256-gcm
ESP aes-256-cbc, aes-256-gcm
ESP aes-256-cbc, aes-256-gcm
ESP aes-256-cbc, aes-256-gcm
ESP 3des
ESP aes-256-cbc
ESP aes-256-cbc, aes-256-gcm
ESP 3des
ESP aes-128-cbc
ESP aes-256-cbc, aes-256-gcm
ESP aes-128-cbc, aes-128-ccm
Status Type
up Auto Key
up Auto Key
up Auto Key
up Auto Key
up Auto Key
unknown Auto Key
up Auto Key
unknown Auto Key
up Auto Key
up Auto Key
up Auto Key
up Auto Key

Source Zone Source Address


DC_Airtel;DC_Vodafone
IP_59.164.64.154;IP_59.164.64.156;IP_118.185.53.118;IP_118.185.53.186;IP_122.15.220.178;IP_123.63.
any IP_172.18.96.110
DC_Airtel;DC_Vodafone any
DC_Airtel;DC_Vodafone any
DC-Core
H_172.18.105.10;H_172.18.105.20;IP_Range-172.18.105.31-36;IP_Range-172.18.105.46-48
DC-Core any
any H_172.18.102.90;H_172.18.102.91
DC_Airtel;DC_Vodafone any
DC_Airtel;DC_Vodafone any
DC_Airtel;DC_Vodafone any
DC_Airtel;DC_Vodafone any
DC_Airtel;DC_Vodafone any
DC_Airtel;DC_Vodafone any
DC_Airtel;DC_Vodafone any
DC_Airtel;DC_Vodafone any
DC_Airtel;DC_Vodafone any
DC_Airtel any
DC_Airtel;DC_Vodafone any
DC-Core any
DC-Core any
any any
any any
DC-Core;VPN any
OfficeLan;VPN any
DC_Airtel;DC_Vodafone any
[Disabled] DC-Core [Disabled] IP_172.18.104.133
DC_Airtel;DC_Vodafone any
any any
any any
Original Packet Source Zone Original Packet Destination Zone
[Disabled] DC-Core [Disabled] DC_Airtel
VPN DC-Core
any DC_Airtel
DC-Core DC_Vodafone
[Disabled] VPN [Disabled] DC-Core
[Disabled] DC-Core [Disabled] VPN
DC-Core DC_Vodafone
DC-Core DC_Airtel
DC_Vodafone DC_Vodafone
DC_Airtel DC_Airtel
DC_Airtel DC_Airtel
[Disabled] any [Disabled] DC-Core
[Disabled] VPN [Disabled] DC-Core
DC_Airtel DC_Airtel
DC_Airtel DC_Airtel
DC_Airtel DC_Airtel
DC-Core DC_Airtel
DC-Core DC_Airtel
DC-Core DC_Airtel
DC-Core DC_Airtel
DC-Core DC_Airtel
DC-Core DC_Airtel
DC-Core DC_Airtel
DC-Core DC_Airtel
DC-Core DC_Vodafone
DC-Core DC_Vodafone
DC-Core DC_Vodafone
DC-Core DC_Vodafone
DC-Core DC_Vodafone
DC-Core DC_Airtel
DC-Core DC_Vodafone
DC_Airtel DC_Airtel
DC-Core DC_Vodafone
DC_Airtel DC_Airtel
any DC_Airtel
DC-Core DC_Vodafone
DC_Airtel DC_Airtel
DC-Core DC_Vodafone
DC-Core DC_Airtel
DC-Core DC_Vodafone
DC-Core DC_Vodafone
DC-Core DC_Vodafone
DC-Core DC_Vodafone
DC-Core DC_Vodafone
DC-Core DC_Vodafone
DC-Core DC_Vodafone
DC-Core DC_Vodafone
DC-Core DC_Vodafone
DC-Core DC_Vodafone
DC-Core DC_Vodafone
DC-Core DC_Vodafone
DC-Core DC_Vodafone
DC-Core DC_Vodafone
DC-Core DC_Vodafone
DC-Core DC_Vodafone
DC_Airtel DC_Airtel
any DC_Airtel
DC-Core DC_Vodafone
DC-Core DC_Vodafone
DC_Airtel DC_Airtel
DC-Core DC_Vodafone
DC_Airtel DC_Airtel
DC-Core DC_Vodafone
DC_Airtel DC_Airtel
DC-Core DC_Airtel
DC-Core DC_Airtel
DC-Core DC_Airtel
DC-Core DC_Airtel
DC-Core DC_Airtel
DC-Core DC_Airtel
DC-Core DC_Vodafone
DC-Core DC_Vodafone
DC-Core DC_Vodafone
DC-Core DC_Vodafone
DC-Core DC_Vodafone
DC-Core DC_Vodafone
DC-Core DC_Vodafone
any DC_Vodafone
OfficeLan DC-Core
DC-Core DC_Vodafone
DC-Core DC_Airtel
[Disabled] DC_Airtel [Disabled] DC_Airtel
DC_Vodafone DC_Vodafone
DC_Airtel DC_Airtel
DC_Airtel DC_Airtel
DC_Airtel DC_Airtel
DC_Airtel DC_Airtel
DC_Airtel DC_Airtel
DC_Airtel DC_Airtel
DC_Airtel DC_Airtel
DC_Airtel DC_Airtel
DC_Airtel DC_Airtel
DC_Airtel DC_Airtel
DC_Airtel DC_Airtel
DC_Airtel DC_Airtel
DC_Airtel DC_Airtel
DC_Airtel DC_Airtel
DC_Airtel DC_Airtel
DC_Airtel DC_Airtel
DC_Airtel DC_Airtel
DC_Airtel DC_Airtel
[Disabled] DC-Core [Disabled] DC_Vodafone

Next Hop interface


tunnel.12
tunnel.12
tunnel.12
tunnel.12
tunnel.12
tunnel.12
tunnel.12
tunnel.12
tunnel.12
tunnel.12
tunnel.12
tunnel.12
tunnel.12
tunnel.12
tunnel.12
tunnel.12
tunnel.12
tunnel.12
172.18.20.2 ethernet1/17
172.18.20.2 ethernet1/17
172.18.20.2 ethernet1/17
tunnel.12
172.18.20.2 ethernet1/17
172.18.20.2 ethernet1/17
tunnel.12
tunnel.12
172.18.20.2 ethernet1/17
tunnel.12
172.18.20.2 ethernet1/17
ethernet1/19
tunnel.5
tunnel.5
tunnel.5
tunnel.2
tunnel.3
tunnel.4
tunnel.8
tunnel.1
tunnel.6
tunnel.6
tunnel.6
tunnel.6
tunnel.6
tunnel.6
tunnel.6
IP Address Virtual Router
123.63.117.249/30;123.63.115.0/24 default
125.18.13.206/30;125.18.115.0/24 default
1.1.1.1/30 default
none none
none none
none none
none none
none none
none none
none none
none none
none none
none none
none none
none none
none none
172.18.20.1/30 default
none none
172.18.10.1/30 default
none none
none default

User ID Enabled User ID Included Networks


Yes any
No any
No any
Yes any
No any
Virtual Router Security Zone
none none
default VPN
default VPN
default VPN
default VPN
default VPN
default VPN
default VPN
default VPN
default VPN
none none
default VPN
default VPN
default VPN

Local Address IP Peer ID ID


125.18.13.206/30
125.18.13.206/30
125.18.13.206/30
125.18.13.206/30
125.18.13.206/30 129.9.200.2
125.18.13.206/30
123.63.117.249/30
125.18.13.206/30
125.18.13.206/30
125.18.13.206/30
125.18.13.206/30
123.63.117.249/30

DH Group Key Lifetime


group2 8 hours
group19 8 hours
group20 8 hours
group2 1440 minutes
group2 1440 minutes
group2 1400 minutes
group2 1440 minutes
group2 1440 minutes
group2 1440 minutes
group2 1440 minutes
group2 8 hours
group2 8 hours
group2 8 hours

Authentication DH Group
sha1 group2
none group19
none group20
sha256 no-pfs
md5 group2
sha256 no-pfs
md5 no-pfs
sha256 no-pfs
sha256 no-pfs
sha1 no-pfs
sha1 no-pfs
sha1 group2
sha1 group2
IKE Gateway/Satellite Interface IKE Gateway/Satellite Local IP
ethernet1/2 125.18.13.206/30
ethernet1/2 125.18.13.206/30
ethernet1/2 125.18.13.206/30
ethernet1/2 125.18.13.206/30
ethernet1/2 125.18.13.206/30
ethernet1/2 125.18.13.206/30
ethernet1/2 125.18.13.206/30
ethernet1/1 123.63.117.249/30
ethernet1/1 123.63.117.249/30
ethernet1/2 125.18.13.206/30
ethernet1/2 125.18.13.206/30
ethernet1/2 125.18.13.206/30

Destination Zone Destination Address


any IP_123.63.115.119;IP_125.18.115.119
DC_Airtel;DC_Vodafone
IP_59.164.64.154;IP_59.164.64.156;IP_118.185.53.118;IP_118.185.53.186;IP_122.15.220.178;IP_123.63.205.
any any
any 123.63.115.77;125.18.115.66
DC_Airtel any
DC_Airtel api.irisgst.com
DC_Airtel;DC_Vodafone any
any 125.18.115.162
DC-Core 123.63.115.125
DC-Core 123.63.115.89;123.63.115.103;EBG_Web_Ext
DC-Core 123.63.115.111;125.18.115.169
DC-Core 123.63.115.107;123.63.115.108;125.18.115.48
DC-Core 123.63.115.106;H_125.18.115.76
DC-Core 123.63.115.92;125.18.115.160
DC-Core 123.63.115.92;125.18.115.160
DC-Core 123.63.115.80
DC-Core 125.18.115.118
DC-Core 123.63.115.109;125.18.115.35
DC_Airtel;DC_Vodafone any
DC_Airtel;DC_Vodafone any
any any
DC-Core 10.2.1.200
OfficeLan;VPN any
DC-Core;VPN any
DC-Core 123.63.115.125;125.18.115.125
[Disabled] DC_Airtel;[Disabled] DC_Vodafone [Disabled] any
DC-Core 123.63.115.89;125.18.115.68
(intrazone) any
any any
Original Packet Destination Interface Original Packet Source Address
[Disabled] any [Disabled] 172.18.96.110
any 172.18.34.202
100.25;H_172.18.100.30;H_172.18.100.40;H_172.18.100.50;H_172.18.100.60;H_172.18.100.80;H_172.18.100.85;H_172.18.100.90;H_
any
any 172.18.96.110
[Disabled] any [Disabled] any
[Disabled] any [Disabled] any
any 172.18.101.50
any 172.18.101.50
ethernet1/1 any
ethernet1/2 any
ethernet1/2 any
[Disabled] any [Disabled] any
[Disabled] any [Disabled] 10.20.135.0/24
ethernet1/2 any
ethernet1/2 any
ethernet1/2 any
ethernet1/2 172.18.105.193
ethernet1/2 172.18.105.250
ethernet1/2 172.18.106.50
ethernet1/2 172.18.106.80
ethernet1/2 172.18.107.210
ethernet1/2 172.18.107.72
ethernet1/2 172.18.31.225
ethernet1/2 172.18.107.160
ethernet1/1 172.18.105.198
ethernet1/1 172.18.105.199
ethernet1/1 172.18.105.223
ethernet1/1 172.18.105.250
ethernet1/1 172.18.106.140
ethernet1/2 172.18.107.143
ethernet1/1 172.18.107.130
ethernet1/2 any
ethernet1/1 172.18.107.220
any any
any H_172.18.107.220
ethernet1/1 172.18.107.31
any any
ethernet1/1 172.18.107.35
ethernet1/2 172.18.107.35
ethernet1/1 172.18.107.41
ethernet1/1 172.18.107.52
ethernet1/1 172.18.107.93
ethernet1/1 172.18.101.74
ethernet1/1 172.18.102.80
ethernet1/1 172.18.102.81
ethernet1/1 172.18.105.193
ethernet1/1 172.18.105.192
ethernet1/1 172.18.105.194
ethernet1/1 172.18.105.196
ethernet1/1 172.18.105.197
ethernet1/1 SAP_WebDispatcher
ethernet1/1 172.18.107.160
ethernet1/1 172.18.107.175
ethernet1/1 172.18.107.180
ethernet1/1 EBG_Web
ethernet1/2 any
ethernet1/2 172.18.107.30
ethernet1/1 172.18.107.72
ethernet1/1 172.18.106.70
ethernet1/2 any
ethernet1/1 172.18.106.71
ethernet1/2 any
ethernet1/1 172.18.106.72
any any
any EBG_Outbound_125.18.115.101
any 172.18.101.73
any 172.18.30.65
any 172.18.96.110;172.18.102.90;172.18.109.15;172.18.109.60;IP_172.18.104.133
any 172.18.102.91;172.18.109.240
any H_172.18.105.10;H_172.18.105.20;IP_Range-172.18.105.31-36;IP_Range-172.18.105.46-48
any 172.18.101.73;172.18.102.70
any 172.18.74.201;172.18.109.120;172.18.109.121;172.18.109.123
any 172.18.73.10
any 172.18.34.251
any 172.18.101.70
any 172.18.100.27;172.18.102.90;172.18.109.15;172.18.109.60
any 172.18.102.91;172.18.109.240
any VodaforneOutboundNAT
ethernet1/3 172.18.10.2
ethernet1/1 any
ethernet1/2 any
] IP_59.164.64.154;[Disabled]
[Disabled]
IP_59.164.64.156;[Disabled]
any IP_118.185.53.118;[Disabled] IP_118.185.53.186;[Disabled] IP_122.15.22
IP_59.164.64.154;IP_118.185.53.186;IP_123.63.205.13;IP_59.164.64.156;IP_122.15.220.178;IP_118.185.53.1
any
any any
any any
any any
any any
any any
any any
any any
any any
any any
any any
any any
any any
any any
any any
any any
any any
any any
any any
[Disabled] any [Disabled] IP_172.18.104.133

Matric
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
metric 10
VLAN / Virtual Wire Security Zone Features Comment
none DC_Vodafone IKE Gateway: Nagpur_IKE_GW_2 Vodafone IIL
none DC_Airtel IKE Gateway: Powai_Office_Airtel_JIO
Airtel IIL
none DC-Core Interface Connecting Primary Core 3232
none none
none none
none none
none none
none none
none none
none none
none none
none none
none none
none none
none none
none none
none DC-Core Interface Connecting Primary Core 3232
none none Interface Connecting Secondary Core 3232
none OfficeLan Interface Connecting Office PA
none none
none none LACPAggregate
Enable Interface of PA and CoreSW 3232

User ID Excluded Networks Device ID Enabled Device ID IncludedDevice


Networks
ID Excluded Networks
none No any none
none No any none
none No any none
none No any none
none No any none
Features Comment

IPSec Tunnel: TAMCO_New_2013 TAMCO VPN TUnnel


IPSec Tunnel: Jebel_Ali Jebel_Ali_VPN
IPSec Tunnel: Indonesia_VPN Indinesia Tunnel
IPSec Tunnel: Saudi Saudi VPN Tunnel
IPSec Tunnel: LT_Tamco_mesh LT Tamco mesh VPN
IPSec Tunnel: EA_SITEL EA Tunnel
IPSec Tunnel: Powai_Office Powai_Office
IPSec Tunnel: LT_Tamcomalaysia_Subang TamcoMalaysia_subang
IPSec Tunnel: Mahape_IPSEC Mahape_Tunnel

IPSec Tunnel: Nagpur_IPSEC_Tunnel Nagpur Tunnel


IPSec Tunnel: Powai_Office_Airtel_JIO Powai_Office_Airtel_JIO
IPSec Tunnel: Nagpur_IPSec_Tunnel_2 Nagpur_Tunnel_2

Peer ID Type Local ID ID Local ID Type Version


125.18.13.206 IP address ikev1
125.18.13.206 IP address ikev1
ikev1
125.18.13.206 IP address ikev1
IP address 125.18.13.206 IP address ikev1
125.18.13.206 IP address ikev1
ikev1
125.18.13.206 IP address ikev1
ikev1
ikev1
ikev1
123.63.117.249 IP address ikev1

Lifetime
1 hours
1 hours
1 hours
3600 seconds
3600 seconds
3600 seconds
3600 seconds
3600 seconds
3600 seconds
28800 seconds
1 hours
1 hours
1 hours
IKE Gateway/Satellite Peer Address IKE Gateway/Satellite Status
Tunnel InterfaceTunnel
Interface
Interface Virtual Router
115.112.41.196 up tunnel.6 default
180.250.57.114 up tunnel.3 default
151.253.7.202 up tunnel.2 default
27.131.52.2 up tunnel.5 default
1.32.62.98 up tunnel.8 default
59.164.64.153 down tunnel.9 default
103.132.207.62 up tunnel.11 default
103.132.204.14 down tunnel.13 default
123.63.229.241 up tunnel.7 default
136.232.254.90 up tunnel.12 default
212.107.103.90 up tunnel.4 default
121.122.44.206 up tunnel.1 default

Application Service Action Profile


any any Allow none
any any Allow none
any service-http;service-https Allow Profile Group: SE_SPG
any service-http;service-https;tcp_8443 Allow none
any service-http;service-https;TCP-53;UDP-53 Allow none
any service-http;service-https Allow none
any any Allow none
any tcp-465;tcp_25 Allow Profile Group: SE_SPG
any service-http;service-https;tcp_44301-44303 Allow Profile Group: SE_SPG
any ftp_989;ftp_990;tcp_1433 Allow Profile Group: SE_SPG
any service-http;service-https;tcp_9251 Allow Profile Group: SE_SPG
any tcp_45-- Allow Profile Group: SE_SPG
any tcp_3000;tcp_4500;tcp_8443 Allow Profile Group: SE_SPG
ftp application-default Allow Profile Group: SE_SPG
any ftp_989;ftp_990;service-http;service-https;tcp_22;tcp_8443
Allow Profile Group: SE_SPG
any service-https;TCP44301-44305 Allow Profile Group: SE_SPG
any service-http;service-https Allow Profile Group: SE_SPG
service-http;service-https;tcp_8010;tcp_8020;tcp_8030;tcp_8031;tcp_8040;tcp_8050;tcp_8060;tcp_8070;tcp_8080;tcp_8090
any Allow Profile Group: SE_SPG
any application-default Allow Profile Group: SE_SPG
any TCP_8089 Allow Profile Group: SE_SPG
icmp;icmpsh;ping;traceroute application-default Allow Profile Group: SE_SPG
any service-http;service-https Allow none
any any Allow none
any any Allow none
any TCP_44303 Allow none
[Disabled] any [Disabled] any [Disabled] Allow none
any ftp_990 Allow none
any any Allow none
any any Deny none
Original Packet Destination Address Original Packet Service
Translated Packet
Translated
Source Translation
Packet Destination Translation
[Disabled] any [Disabled]
[Disabled]
static-ip;[Disabled]
any IP_125.18.115.119;[Disabled]
none bi-directional: no
any any
dynamic-ip-and-port;ethernet1/17;172.18.20.1/30
none
any any dynamic-ip-and-port;H_125.18.115.69 none
any any static-ip;IP_123.63.115.119;bi-directional:
noneno
[Disabled] any [Disabled] any [Disabled] none none
[Disabled] any [Disabled] any [Disabled] none none
any any static-ip;123.63.115.75;bi-directional:none
yes
any any static-ip;125.18.115.162;bi-directional:none
yes
123.63.115.106 any destination-translation;address:
none 172.18.107.62
125.18.115.76 any destination-translation;address:
none 172.18.107.62
125.18.115.162 any destination-translation;address:
none 172.18.101.50
[Disabled] 172.18.20.2 [Disabled][Disabled]
dynamic-ip-and-port;[Disabled]
any ethernet1/17;[Disabled]
none 172.18.20.1/30
[Disabled] any [Disabled][Disabled]
dynamic-ip-and-port;[Disabled]
any ethernet1/17;[Disabled]
none 172.18.20.1/30
125.18.115.161 any destination-translation;address:
none 172.18.107.170
125.18.115.151 any destination-translation;address:
none 172.18.105.192
125.18.115.254 any destination-translation;address:
none 172.18.102.81
any any static-ip;125.18.115.23;bi-directional:none
yes
any any static-ip;125.18.115.35;bi-directional:none
yes
any any static-ip;125.18.115.43;bi-directional:none
yes
any any static-ip;125.18.115.160;bi-directional:none
yes
any any static-ip;125.18.115.52;bi-directional:none
yes
any any static-ip;125.18.115.48;bi-directional:none
yes
any any static-ip;125.18.115.41;bi-directional:none
yes
any any static-ip;125.18.115.13;bi-directional:none
yes
any any static-ip;123.63.115.115;bi-directional:none
yes
any any static-ip;123.63.115.113;bi-directional:none
yes
any any static-ip;123.63.115.125;bi-directional:none
yes
any any static-ip;123.63.115.109;bi-directional:none
yes
any any static-ip;123.63.115.89;bi-directional:none
yes
any any static-ip;125.18.115.118;bi-directional:none
yes
any any static-ip;123.63.115.111;bi-directional:none
yes
125.18.115.169 any destination-translation;address:
none 172.18.107.130
any any static-ip;123.63.115.88;bi-directional:none
yes
125.18.115.26 any destination-translation;address:
none 172.18.107.220
any any dynamic-ip-and-port;H_125.18.115.26 none
any any static-ip;123.63.115.110;bi-directional:none
yes
125.18.115.102 any destination-translation;address:
none 172.18.107.35
any any static-ip;123.63.115.86;bi-directional:none
yes
any any static-ip;125.18.115.102;bi-directional:none
no
any any static-ip;123.63.115.77;bi-directional:none
yes
any any static-ip;123.63.115.105;bi-directional:none
yes
any any static-ip;123.63.115.108;bi-directional:none
yes
any any static-ip;123.63.115.122;bi-directional:none
yes
any any static-ip;123.63.115.102;bi-directional:none
yes
any any static-ip;123.63.115.92;bi-directional:none
yes
any any static-ip;123.63.115.70;bi-directional:none
yes
any any static-ip;123.63.115.71;bi-directional:none
yes
any any static-ip;123.63.115.116;bi-directional:
none
yes
any any static-ip;123.63.115.114;bi-directional:
none
yes
any any static-ip;123.63.115.112;bi-directional:
none
yes
any any static-ip;123.63.115.80;bi-directional:none
yes
any any static-ip;123.63.115.91;bi-directional:none
yes
any any static-ip;123.63.115.98;bi-directional:none
yes
any any static-ip;123.63.115.97;bi-directional:none
yes
any any static-ip;EBG_Web_Ext;bi-directional:noneyes
125.18.115.47 any destination-translation;address:
none 172.18.107.30
any any dynamic-ip-and-port;125.18.115.47 none
any any static-ip;123.63.115.107;bi-directional:
none
yes
any any static-ip;123.63.115.72;bi-directional:none
yes
125.18.115.152 any destination-translation;address:
none 172.18.106.70
any any static-ip;123.63.115.73;bi-directional:none
yes
125.18.115.153 any destination-translation;address:
none 172.18.106.71
any any static-ip;123.63.115.74;bi-directional:none
yes
125.18.115.65 any destination-translation;address:
none 172.18.106.72
any any dynamic-ip-and-port;125.18.115.101 none
any any static-ip;125.18.18.112;bi-directional:none
no
any any static-ip;123.63.115.76;bi-directional:none
no
any any dynamic-ip-and-port;125.18.115.165 none
any any dynamic-ip-and-port;125.18.115.95 none
any any dynamic-ip-and-port;125.18.115.95 none
any any dynamic-ip-and-port;123.63.115.67 none
any any dynamic-ip-and-port;123.63.115.121 none
any any static-ip;123.15.128.113;bi-directional:
none
no
any any static-ip;123.63.115.71;bi-directional:none
no
any any static-ip;123.63.115.93;bi-directional:none
no
any any dynamic-ip-and-port;123.63.115.95 none
any any dynamic-ip-and-port;123.63.115.100 none
any any dynamic-ip-and-port;123.63.115.76 none
any any
dynamic-ip-and-port;ethernet1/17;172.18.20.1/30
none
any any
dynamic-ip-and-port;ethernet1/1;123.63.117.249/30
none
any any
dynamic-ip-and-port;ethernet1/2;125.18.13.206/30
none
[Disabled] IP_125.18.115.119 [Disabled] any[Disabled][Disabled]
destination-translation;[Disabled]
none address: IP_172.
IP_123.63.115.119 any destination-translation;address:
none IP_172.18.96.110
125.18.115.118 any destination-translation;address:
none H_172.18.107.143
125.18.115.66 any destination-translation;address:
none 172.18.107.41
125.18.115.68 any destination-translation;address:
none 172.18.106.140
125.18.115.71 any destination-translation;address:
none 172.18.107.175
125.18.115.74 any destination-translation;address:
none 172.18.107.40
125.18.115.75 any destination-translation;address:
none 172.18.107.50
125.18.115.34 any destination-translation;address:
none 172.18.107.93
125.18.115.77 any destination-translation;address:
none 172.18.107.31
125.18.115.112 any destination-translation;address:
none 172.18.105.197
125.18.115.115 any destination-translation;address:
none 172.18.105.198
125.18.115.116 any destination-translation;address:
none 172.18.105.194
125.18.115.117 any destination-translation;address:
none 172.18.105.251
125.18.115.114 any destination-translation;address:
none 172.18.105.196
125.18.115.113 any destination-translation;address:
none 172.18.105.199
125.18.115.121 any destination-translation;address:
none 172.18.107.36
125.18.115.122 any destination-translation;address:
none 172.18.101.74
125.18.115.125 any destination-translation;address:
none 172.18.105.223
125.18.115.24 any destination-translation;address:
none 172.18.107.20
[Disabled] any [Disabled]
[Disabled]
static-ip;[Disabled]
any 123.63.115.90;[Disabled]
nonebi-directional: yes
Primary Core 3232

Primary Core 3232


econdary Core 3232
cting Office PA

PA and CoreSW 3232

ded Networks
IKE Advanced
IKE Advanced
Options
IKEOptions
Advanced
Mode IKE
Passive
Options
Advanced
Mode
NATOptions
IKE
Traversal
Advanced
Crypto
IKE Advanced
Profile
Options DPD
OptionsComment
Liveness
auto No No TAMCO_IKE
enabled/default/default
auto No No Jebel_IKE
enabled/default/default
auto No No Indonesia_IKE
enabled/default/default
auto Yes No Saudi
enabled/default/default
auto No No LT_Tamco
enabled/default/default
auto No No EA_SITEL
enabled/default/default
auto No No default
enabled/default/default
auto No LT_Tamcomalaysia_subang
No enabled/default/default
auto No No Mahape
enabled/default/default
Mahape Tunnel with Powai Airtel
auto No NoNagpur_IKE_Crypto
enabled/default/default
auto No No default
enabled/default/default
auto No NoNagpur_IKE_Crypto
enabled/default/default
Tunnel Interface
TunnelVirtual
Interface
System
Tunnel
Security
Interface
Zone Status
Comment
vsys1 VPN up
vsys1 VPN up
vsys1 VPN up
vsys1 VPN up
vsys1 VPN up
vsys1 VPN Mahape
up to Powai Airtel Tunnel
vsys1 VPN upNagpur IPSEC Tunnel
vsys1 VPN Nagpur
up IPSec Secondary Tunnel
vsys1 VPN up
vsys1 VPN up
vsys1 VPN up
vsys1 VPN up
tination Translation

ddress: 172.18.107.62
ddress: 172.18.107.62
ddress: 172.18.101.50

ddress: 172.18.107.170
ddress: 172.18.105.192
ddress: 172.18.102.81

ddress: 172.18.107.130

ddress: 172.18.107.220

ddress: 172.18.107.35
ddress: 172.18.107.30

ddress: 172.18.106.70

ddress: 172.18.106.71

ddress: 172.18.106.72

sabled] address: IP_172.18.96.110


dress: IP_172.18.96.110
dress: H_172.18.107.143
ddress: 172.18.107.41
ddress: 172.18.106.140
ddress: 172.18.107.175
ddress: 172.18.107.40
ddress: 172.18.107.50
ddress: 172.18.107.93
ddress: 172.18.107.31
ddress: 172.18.105.197
ddress: 172.18.105.198
ddress: 172.18.105.194
ddress: 172.18.105.251
ddress: 172.18.105.196
ddress: 172.18.105.199
ddress: 172.18.107.36
ddress: 172.18.101.74
ddress: 172.18.105.223
ddress: 172.18.107.20
Sr. No. Parameter

1 Location

2 Local Contact Person

3 Device Model
4 Network Architecture
5 OS Version
6 Management IP and mask
7 Hostname
8 DNS Server IP
9 NTP Server IP

10 Interface Configuration

11 Interface IP / Network

12 Zone Name & Mapping


13 HA Mode
IPSec Tunnel Details
14
(Provide filled VPN Template)
15 Virtual router Name
Routing Protocol (Static/Dynamic)
16
Static Routes details
17 Address Object/Service Object details
Security/Access Policy details
18
NAT Policy details
Remote Logging and Remote
19
Management / Authentication details

Site-to-Site VPN Form


Parameter Site1
Location
Administrator's Name
Administrator's Contact
Administrator's Email
Vendor Case ID (Optional)
IKE-Phase1
Local IP
IKE Hash SHA256
IKE Encrypti AES256
IKE Aggress Auto
Renegotiate 86400secs
IKE Diffie-H 14
NAT traversal
IKE keep alive
Preshared key
Dead Peer De 5secs
IPSEC-Phase2
IPSEC Hash SHA256
IPSEC Encry AES256
IPSEC Perfec Group 14
Force key expiration
Renegotiate 3600secs
Renegotiate IPSEC SA Every (kb)
Encryption Domain (Interesting Traffic)
Network 1
Network 2
Network 3

Interface Details

Interface Interface Type

Zone Details

Name Type

Address Object Details

SR Name

Address Group details

SR Name
Service Object details

Sr. Name

Security Policies

Sr. Name

NAT Rules

Sr Name

Static Routes Details

Name Destination IP
Details
EAIC DR
NxtGen Data Center & Cloud Plot No. 25-P-13, Bidadi industrial
Area, Ramanagar Dist – 562109
LPL Ranganath
[email protected]
PA850 + PA850 HA

9.1.5

1/1 - Primary Internet


1/2 - LAN
1/3 - DMZ (reserved)
1/4 - DMZ (reserved)
1/5 - Secondary Internet (if any)
WAN -
LAN -
DMZ -
HA1 -
HA2 -

Active-Passive
Count -
Spoke Locations -
Default-VR
Static
Provide Static Route Template
As per Security Policy Template
Provide Security Policy Template
Provide Security Policy Template
Local Authentication and logging

Site-to-Site VPN Form


Site2

IKE-Phase1
IPSEC-Phase2

yption Domain (Interesting Traffic)

Management Profile Link State IP Address


Virtual Router
VLAN / Virtual Wire

Interfaces / Virtual Systems Zone Protection


User
Profile
ID
User
Enabled
ID Included
User IDNetworks
Excluded Networks

Type Address

Addresses
Protocol Destination Port

Source Zone Source Address


Destination
Destination
Zone Address
Application

Original Packet Source Zone Original Packet


OriginalDestination
Packet
Original
Destination
Zone
Original
PacketInterface
Source
PacketAddress
Destination Address

Next Hop interface Matric


Security ZoneFeatures Comment

Device
Device
ID Enabled
ID Included
Device IDNetworks
Excluded Networks
Service Action Profile

Original
Translated
Packet
Translated
Packet
ServiceSource
PacketTranslation
Destination Translation
Sr. No. Parameter

1 Location

2 Local Contact Person

3 Device Model
4 Network Architecture
5 OS Version
6 Management IP and mask
7 Hostname
8 DNS Server IP
9 NTP Server IP

10 Interface Configuration

11 Interface IP / Network

12 Zone Name & Mapping


13 HA Mode
IPSec Tunnel Details
14
(Provide filled VPN Template)
15 Virtual router Name
Routing Protocol (Static/Dynamic)
16
Static Routes details
17 Address Object/Service Object details
Security/Access Policy details
18
NAT Policy details
Remote Logging and Remote
19
Management / Authentication details
Details
Nagpur DC
L&T Electrical & Automation (A Unit of SEIPL), ESP Nagpur
Stocking Plant, Survey No. 332/1, C. O. Logistics Park, NH6,
Amravati Road, Nimji Kalmeshwar, Nagpur - 441501,
Maharashtra
Ravi Patil
9881741740, [email protected]
PA850 + PA850 HA

9.1.5

1/1 - Primary Internet


1/2 - LAN
1/3 - DMZ (reserved)
1/4 - DMZ (reserved)
1/5 - Secondary Internet (if any)
WAN -
LAN -
DMZ -
HA1 -
HA2 -

Active-Passive
Count -
Spoke Locations -
Default-VR
Static
Provide Static Route Template
As per Security Policy Template
Provide Security Policy Template
Provide Security Policy Template
Local Authentication and logging
Sr. No. Parameter

1 Location

2 Local Contact Person

3 Device Model
4 Network Architecture
5 OS Version
6 Management IP and mask
7 Hostname
8 DNS Server IP
9 NTP Server IP

10 Interface Configuration

11 Interface IP / Network

12 Zone Name & Mapping


IPSec Tunnel Details
13
(Provide filled VPN Template)
14 Virtual router Name
Routing Protocol (Static/Dynamic)
15
Static Routes details
16 Address Object/Service Object details
Security/Access Policy details
17
NAT Policy details
Remote Logging and Remote
18
Management / Authentication details

Site-to-Site VPN Form


Parameter Site1
Location
Administrator's Name
Administrator's Contact
Administrator's Email
Vendor Case ID (Optional)
IKE-Phase1
Local IP
IKE Hash SHA256
IKE Encrypti AES256
IKE Aggress Auto
Renegotiate 86400secs
IKE Diffie-H 14
NAT traversal
IKE keep alive
Preshared key
Dead Peer De 5secs
IPSEC-Phase2
IPSEC Hash SHA256
IPSEC Encry AES256
IPSEC Perfec Group 14
Force key expiration
Renegotiate 3600secs
Renegotiate IPSEC SA Every (kb)
Encryption Domain (Interesting Traffic)
Network 1
Network 2
Network 3

Interface Details

Interface Interface Type

Zone Details

Name Type

Address Object Details

SR Name

Address Group details

SR Name
Service Object details

Sr. Name

Security Policies

Sr. Name

NAT Rules

Sr Name

Static Routes Details

Name Destination IP
Details
Kolkata DC
L&T Electrical & Automation (A Unit of SEIPL), ESP Hawrah
Stocking Plant, C/o TK Exim Pvt Ltd, Everbright Warehouse
Complex, Khaitan No216, Chamrail, Howrah - 711114, West
Bengal
Kaustav Goswami
9433728208, [email protected]
PA820

9.1.5

1/1 - Primary Internet


1/2 - LAN
1/3 - DMZ (reserved)
1/4 - DMZ (reserved)
1/5 - Secondary Internet (if any)
WAN -
LAN -
DMZ -

Count -
Spoke Locations -
Default-VR
Static
Provide Static Route Template
As per Security Policy Template
Provide Security Policy Template
Provide Security Policy Template
Local Authentication and logging

Site-to-Site VPN Form


Site2

IKE-Phase1
IPSEC-Phase2

yption Domain (Interesting Traffic)

Management Profile Link State IP Address


Virtual Router
VLAN / Virtual Wire

Interfaces / Virtual Systems Zone Protection


User
Profile
ID
User
Enabled
ID Included
User IDNetworks
Excluded Networks

Type Address

Addresses
Protocol Destination Port

Source Zone Source Address


Destination
Destination
Zone Address
Application

Original Packet Source Zone Original Packet


OriginalDestination
Packet
Original
Destination
Zone
Original
PacketInterface
Source
PacketAddress
Destination Address

Next Hop interface Matric


Security ZoneFeatures Comment

Device
Device
ID Enabled
ID Included
Device IDNetworks
Excluded Networks
Service Action Profile

Original
Translated
Packet
Translated
Packet
ServiceSource
PacketTranslation
Destination Translation
Sr. No. Parameter

1 Location

2 Local Contact Person


3 Device Model
4 Network Architecture
5 OS Version
6 Management IP and mask
7 Hostname
8 DNS Server IP
9 NTP Server IP

10 Interface Configuration

11 Interface IP / Network

12 Zone Name & Mapping


13 HA Mode
IPSec Tunnel Details
14
(Provide filled VPN Template)
15 Virtual router Name
Routing Protocol (Static/Dynamic)
16
Static Routes details
17 Address Object/Service Object details
Security/Access Policy details
18
NAT Policy details
Remote Logging and Remote
19
Management / Authentication details

Site-to-Site VPN Form


Parameter Site1
Location
Administrator's Name
Administrator's Contact
Administrator's Email
Vendor Case ID (Optional)
IKE-Phase1
Local IP
IKE Hash SHA256
IKE Encrypti AES256
IKE Aggress Auto
Renegotiate 86400secs
IKE Diffie-H 14
NAT traversal
IKE keep alive
Preshared key
Dead Peer De 5secs
IPSEC-Phase2
IPSEC Hash SHA256
IPSEC Encry AES256
IPSEC Perfec Group 14
Force key expiration
Renegotiate 3600secs
Renegotiate IPSEC SA Every (kb)
Encryption Domain (Interesting Traffic)
Network 1
Network 2
Network 3

Interface Details

Interface Interface Type

Zone Details

Name Type

Address Object Details

SR Name

Address Group details

SR Name
Service Object details

Sr. Name

Security Policies

Sr. Name

NAT Rules

Sr Name

Static Routes Details

Name Destination IP
Details
R&D (STL)
Schneider Electric India Pvt. Ltd. STL Building, Gate No-1, Saki
Vihar Road, Powai, Mumbai 400 072
Virendra Bura / +91-9987796162
PA850 + PA850 HA

9.1.5

1/1 - Primary Internet


1/2 - LAN
1/3 - DMZ (reserved)
1/4 - DMZ (reserved)
1/5 - Secondary Internet (if any)
WAN -
LAN -
DMZ -
HA1 -
HA2 -

Active-Passive
Count -
Spoke Locations -
Default-VR
Static
Provide Static Route Template
As per Security Policy Template
Provide Security Policy Template
Provide Security Policy Template
Local Authentication and logging

Site-to-Site VPN Form


Site2

IKE-Phase1
IPSEC-Phase2

yption Domain (Interesting Traffic)

Management Profile Link State IP Address


Virtual Router
VLAN / Virtual Wire

Interfaces / Virtual Systems Zone Protection


User
Profile
ID
User
Enabled
ID Included
User IDNetworks
Excluded Networks

Type Address

Addresses
Protocol Destination Port

Source Zone Source Address


Destination
Destination
Zone Address
Application

Original Packet Source Zone Original Packet


OriginalDestination
Packet
Original
Destination
Zone
Original
PacketInterface
Source
PacketAddress
Destination Address

Next Hop interface Matric


Security ZoneFeatures Comment

Device
Device
ID Enabled
ID Included
Device IDNetworks
Excluded Networks
Service Action Profile

Original
Translated
Packet
Translated
Packet
ServiceSource
PacketTranslation
Destination Translation
Sr. No. Parameter

1 Location

2 Local Contact Person

3 Device Model
4 Network Architecture
5 OS Version
6 Management IP and mask
7 Hostname
8 DNS Server IP
9 NTP Server IP

10 Interface Configuration

11 Interface IP / Network

12 Zone Name & Mapping


13 HA Mode
IPSec Tunnel Details
14
(Provide filled VPN Template)
15 Virtual router Name
Routing Protocol (Static/Dynamic)
16
Static Routes details
17 Address Object/Service Object details
Security/Access Policy details
18
NAT Policy details
Remote Logging and Remote
19
Management / Authentication details

Site-to-Site VPN Form


Parameter Site1
Location
Administrator's Name
Administrator's Contact
Administrator's Email
Vendor Case ID (Optional)
IKE-Phase1
Local IP
IKE Hash SHA256
IKE Encrypti AES256
IKE Aggress Auto
Renegotiate 86400secs
IKE Diffie-H 14
NAT traversal
IKE keep alive
Preshared key
Dead Peer De 5secs
IPSEC-Phase2
IPSEC Hash SHA256
IPSEC Encry AES256
IPSEC Perfec Group 14
Force key expiration
Renegotiate 3600secs
Renegotiate IPSEC SA Every (kb)
Encryption Domain (Interesting Traffic)
Network 1
Network 2
Network 3

Interface Details

Interface Interface Type

Zone Details

Name Type

Address Object Details

SR Name

Address Group details

SR Name
Service Object details

Sr. Name

Security Policies

Sr. Name

NAT Rules

Sr Name

Static Routes Details

Name Destination IP
Details
Ahmednagar Factory
Schneider Electric India Private Limited, L&T Electrical &
Automation, A-9 MIDC Area, Ahmednagar-414111 (MS)

Swapnil S Ostwal +919421788887 [email protected]

PA3220 + PA3220 HA

9.1.5

1/1 - Primary Internet


1/2 - LAN
1/3 - DMZ (reserved)
1/4 - DMZ (reserved)
1/5 - Secondary Internet (if any)
WAN -
LAN -
DMZ -
HA1 -
HA2 -

Active-Passive
Count -
Spoke Locations -
Default-VR
Static
Provide Static Route Template
As per Security Policy Template
Provide Security Policy Template
Provide Security Policy Template
Local Authentication and logging

Site-to-Site VPN Form


Site2

IKE-Phase1
IPSEC-Phase2

yption Domain (Interesting Traffic)

Management Profile Link State IP Address


Virtual Router
VLAN / Virtual Wire

Interfaces / Virtual Systems Zone Protection


User
Profile
ID
User
Enabled
ID Included
User IDNetworks
Excluded Networks

Type Address

Addresses
Protocol Destination Port

Source Zone Source Address


Destination
Destination
Zone Address
Application

Original Packet Source Zone Original Packet


OriginalDestination
Packet
Original
Destination
Zone
Original
PacketInterface
Source
PacketAddress
Destination Address

Next Hop interface Matric


Security ZoneFeatures Comment

Device
Device
ID Enabled
ID Included
Device IDNetworks
Excluded Networks
Service Action Profile

Original
Translated
Packet
Translated
Packet
ServiceSource
PacketTranslation
Destination Translation
Sr. No. Parameter

1 Location

2 Local Contact Person

3 Device Model
4 Network Architecture
5 OS Version
6 Management IP and mask
7 Hostname
8 DNS Server IP
9 NTP Server IP

10 Interface Configuration

11 Interface IP / Network

12 Zone Name & Mapping


13 HA Mode
IPSec Tunnel Details
14
(Provide filled VPN Template)
15 Virtual router Name
Routing Protocol (Static/Dynamic)
16
Static Routes details
17 Address Object/Service Object details
Security/Access Policy details
18
NAT Policy details
Remote Logging and Remote
19
Management / Authentication details

Site-to-Site VPN Form


Parameter Site1
Location
Administrator's Name
Administrator's Contact
Administrator's Email
Vendor Case ID (Optional)
IKE-Phase1
Local IP
IKE Hash SHA256
IKE Encrypti AES256
IKE Aggress Auto
Renegotiate 86400secs
IKE Diffie-H 14
NAT traversal
IKE keep alive
Preshared key
Dead Peer De 5secs
IPSEC-Phase2
IPSEC Hash SHA256
IPSEC Encry AES256
IPSEC Perfec Group 14
Force key expiration
Renegotiate 3600secs
Renegotiate IPSEC SA Every (kb)
Encryption Domain (Interesting Traffic)
Network 1
Network 2
Network 3

Interface Details

Interface Interface Type

Zone Details

Name Type

Address Object Details

SR Name

Address Group details

SR Name
Service Object details

Sr. Name

Security Policies

Sr. Name

NAT Rules

Sr Name

Static Routes Details

Name Destination IP
Details
Mahape Factory
Schneider Electric India Private Limited, L&T Electrical &
Automation, A-600 TTC Indistrial Area , Shail Mahape Road ,
Navi Mumbai 400710
Manish Desai
9930991936 [email protected]
PA3220 + PA3220 HA

9.1.5

1/1 - Primary Internet


1/2 - LAN
1/3 - DMZ (reserved)
1/4 - DMZ (reserved)
1/5 - Secondary Internet (if any)
WAN -
LAN -
DMZ -
HA1 -
HA2 -

Active-Passive
Count -
Spoke Locations -
Default-VR
Static
Provide Static Route Template
As per Security Policy Template
Provide Security Policy Template
Provide Security Policy Template
Local Authentication and logging

Site-to-Site VPN Form


Site2

IKE-Phase1
IPSEC-Phase2

yption Domain (Interesting Traffic)

Management Profile Link State IP Address


Virtual Router
VLAN / Virtual Wire

Interfaces / Virtual Systems Zone Protection


User
Profile
ID
User
Enabled
ID Included
User IDNetworks
Excluded Networks

Type Address

Addresses
Protocol Destination Port

Source Zone Source Address


Destination
Destination
Zone Address
Application

Original Packet Source Zone Original Packet


OriginalDestination
Packet
Original
Destination
Zone
Original
PacketInterface
Source
PacketAddress
Destination Address

Next Hop interface Matric


Security ZoneFeatures Comment

Device
Device
ID Enabled
ID Included
Device IDNetworks
Excluded Networks
Service Action Profile

Original
Translated
Packet
Translated
Packet
ServiceSource
PacketTranslation
Destination Translation
Sr. No. Parameter

1 Location

2 Local Contact Person

3 Device Model
4 Network Architecture
5 OS Version
6 Management IP and mask
7 Hostname
8 DNS Server IP
9 NTP Server IP

10 Interface Configuration

11 Interface IP / Network

12 Zone Name & Mapping


13 HA Mode
IPSec Tunnel Details
14
(Provide filled VPN Template)
15 Virtual router Name
Routing Protocol (Static/Dynamic)
16
Static Routes details
17 Address Object/Service Object details
Security/Access Policy details
18
NAT Policy details
Remote Logging and Remote
19
Management / Authentication details

Site-to-Site VPN Form


Parameter Site1
Location
Administrator's Name
Administrator's Contact
Administrator's Email
Vendor Case ID (Optional)
IKE-Phase1
Local IP
IKE Hash SHA256
IKE Encrypti AES256
IKE Aggress Auto
Renegotiate 86400secs
IKE Diffie-H 14
NAT traversal
IKE keep alive
Preshared key
Dead Peer De 5secs
IPSEC-Phase2
IPSEC Hash SHA256
IPSEC Encry AES256
IPSEC Perfec Group 14
Force key expiration
Renegotiate 3600secs
Renegotiate IPSEC SA Every (kb)
Encryption Domain (Interesting Traffic)
Network 1
Network 2
Network 3

Interface Details

Interface Interface Type

Zone Details

Name Type

Address Object Details

SR Name

Address Group details

SR Name
Service Object details

Sr. Name

Security Policies

Sr. Name

NAT Rules

Sr Name

Static Routes Details

Name Destination IP
Details
Vadodara Factory
Schneider Electric India Private Limited, L&T Electrical &
Automation, Behind L&T Knowledge City,Near Village Ankhol,
Vadodara - 390 019, Tel. : +91 265 614 7766
Vishal Shah +91 97275 81950
[email protected]
PA3220 + PA3220 HA

9.1.5

1/1 - Primary Internet


1/2 - LAN
1/3 - DMZ (reserved)
1/4 - DMZ (reserved)
1/5 - Secondary Internet (if any)
WAN -
LAN -
DMZ -
HA1 -
HA2 -

Active-Passive
Count -
Spoke Locations -
Default-VR
Static
Provide Static Route Template
As per Security Policy Template
Provide Security Policy Template
Provide Security Policy Template
Local Authentication and logging

Site-to-Site VPN Form


Site2

IKE-Phase1
IPSEC-Phase2

yption Domain (Interesting Traffic)

Management Profile Link State IP Address


Virtual Router
VLAN / Virtual Wire

Interfaces / Virtual Systems Zone Protection


User
Profile
ID
User
Enabled
ID Included
User IDNetworks
Excluded Networks

Type Address

Addresses
Protocol Destination Port

Source Zone Source Address


Destination
Destination
Zone Address
Application

Original Packet Source Zone Original Packet


OriginalDestination
Packet
Original
Destination
Zone
Original
PacketInterface
Source
PacketAddress
Destination Address

Next Hop interface Matric


Security ZoneFeatures Comment

Device
Device
ID Enabled
ID Included
Device IDNetworks
Excluded Networks
Service Action Profile

Original
Translated
Packet
Translated
Packet
ServiceSource
PacketTranslation
Destination Translation
Sr. No. Parameter

1 Location

2 Local Contact Person

3 Device Model
4 Network Architecture
5 OS Version
6 Management IP and mask
7 Hostname
8 DNS Server IP
9 NTP Server IP

10 Interface Configuration

11 Interface IP / Network

12 Zone Name & Mapping


13 HA Mode
IPSec Tunnel Details
14
(Provide filled VPN Template)
15 Virtual router Name
Routing Protocol (Static/Dynamic)
16
Static Routes details
17 Address Object/Service Object details
Security/Access Policy details
18
NAT Policy details
Remote Logging and Remote
19
Management / Authentication details

Site-to-Site VPN Form


Parameter Site1
Location
Administrator's Name
Administrator's Contact
Administrator's Email
Vendor Case ID (Optional)
IKE-Phase1
Local IP
IKE Hash SHA256
IKE Encrypti AES256
IKE Aggress Auto
Renegotiate 86400secs
IKE Diffie-H 14
NAT traversal
IKE keep alive
Preshared key
Dead Peer De 5secs
IPSEC-Phase2
IPSEC Hash SHA256
IPSEC Encry AES256
IPSEC Perfec Group 14
Force key expiration
Renegotiate 3600secs
Renegotiate IPSEC SA Every (kb)
Encryption Domain (Interesting Traffic)
Network 1
Network 2
Network 3

Interface Details

Interface Interface Type

Zone Details

Name Type

Address Object Details

SR Name

Address Group details

SR Name
Service Object details

Sr. Name

Security Policies

Sr. Name

NAT Rules

Sr Name

Static Routes Details

Name Destination IP
Details
Mysore Factory
Schneider Electric India Private Limited, L&T Electrical &
Automation, Gate No. 1, KIADB Industrial Area, Hebbal,
Hootagalli, Mysore - 570018
Arun Solomon
9342120533 [email protected]
PA3220 + PA3220 HA

9.1.5

1/1 - Primary Internet


1/2 - LAN
1/3 - DMZ (reserved)
1/4 - DMZ (reserved)
1/5 - Secondary Internet (if any)
WAN -
LAN -
DMZ -
HA1 -
HA2 -

Active-Passive
Count -
Spoke Locations -
Default-VR
Static
Provide Static Route Template
As per Security Policy Template
Provide Security Policy Template
Provide Security Policy Template
Local Authentication and logging

Site-to-Site VPN Form


Site2

IKE-Phase1
IPSEC-Phase2

yption Domain (Interesting Traffic)

Management Profile Link State IP Address


Virtual Router
VLAN / Virtual Wire

Interfaces / Virtual Systems Zone Protection


User
Profile
ID
User
Enabled
ID Included
User IDNetworks
Excluded Networks

Type Address

Addresses
Protocol Destination Port

Source Zone Source Address


Destination
Destination
Zone Address
Application

Original Packet Source Zone Original Packet


OriginalDestination
Packet
Original
Destination
Zone
Original
PacketInterface
Source
PacketAddress
Destination Address

Next Hop interface Matric


Security ZoneFeatures Comment

Device
Device
ID Enabled
ID Included
Device IDNetworks
Excluded Networks
Service Action Profile

Original
Translated
Packet
Translated
Packet
ServiceSource
PacketTranslation
Destination Translation
Sr. No. Parameter

1 Location

2 Local Contact Person


3 Device Model
4 Network Architecture
5 OS Version
6 Management IP and mask
7 Hostname
8 DNS Server IP
9 NTP Server IP

10 Interface Configuration

11 Interface IP / Network

12 Zone Name & Mapping


13 HA Mode
IPSec Tunnel Details
14
(Provide filled VPN Template)
15 Virtual router Name
Routing Protocol (Static/Dynamic)
16
Static Routes details
17 Address Object/Service Object details
Security/Access Policy details
18
NAT Policy details
Remote Logging and Remote
19
Management / Authentication details

Site-to-Site VPN Form


Parameter Site1
Location
Administrator's Name
Administrator's Contact
Administrator's Email
Vendor Case ID (Optional)
IKE-Phase1
Local IP
IKE Hash SHA256
IKE Encrypti AES256
IKE Aggress Auto
Renegotiate 86400secs
IKE Diffie-H 14
NAT traversal
IKE keep alive
Preshared key
Dead Peer De 5secs
IPSEC-Phase2
IPSEC Hash SHA256
IPSEC Encry AES256
IPSEC Perfec Group 14
Force key expiration
Renegotiate 3600secs
Renegotiate IPSEC SA Every (kb)
Encryption Domain (Interesting Traffic)
Network 1
Network 2
Network 3

Interface Details

Interface Interface Type

Zone Details

Name Type

Address Object Details

SR Name

Address Group details

SR Name
Service Object details

Sr. Name

Security Policies

Sr. Name

NAT Rules

Sr Name

Static Routes Details

Name Destination IP
Details
Coimbatore Factory
L&T Electrical & Automation, Switchgear Design and
Development Centre, Building E3A, Coimbatore Campus, L&T
Bypass Road, Malumichampatti, Coimbatore -641050
Mahendra S [email protected] 8807150466
PA3220 + PA3220 HA

9.1.5

1/1 - Primary Internet


1/2 - LAN
1/3 - DMZ (reserved)
1/4 - DMZ (reserved)
1/5 - Secondary Internet (if any)
WAN -
LAN -
DMZ -
HA1 -
HA2 -

Active-Passive
Count -
Spoke Locations -
Default-VR
Static
Provide Static Route Template
As per Security Policy Template
Provide Security Policy Template
Provide Security Policy Template
Local Authentication and logging

Site-to-Site VPN Form


Site2

IKE-Phase1
IPSEC-Phase2

yption Domain (Interesting Traffic)

Management Profile Link State IP Address


Virtual Router
VLAN / Virtual Wire

Interfaces / Virtual Systems Zone Protection


User
Profile
ID
User
Enabled
ID Included
User IDNetworks
Excluded Networks

Type Address

Addresses
Protocol Destination Port

Source Zone Source Address


Destination
Destination
Zone Address
Application

Original Packet Source Zone Original Packet


OriginalDestination
Packet
Original
Destination
Zone
Original
PacketInterface
Source
PacketAddress
Destination Address

Next Hop interface Matric


Security ZoneFeatures Comment

Device
Device
ID Enabled
ID Included
Device IDNetworks
Excluded Networks
Service Action Profile

Original
Translated
Packet
Translated
Packet
ServiceSource
PacketTranslation
Destination Translation
Sr. No. Parameter

1 Location

2 Local Contact Person


3 Device Model
4 Network Architecture
5 OS Version
6 Management IP and mask
7 Hostname
8 DNS Server IP
9 NTP Server IP

10 Interface Configuration

11 Interface IP / Network

12 Zone Name & Mapping


IPSec Tunnel Details
13
(Provide filled VPN Template)
14 Virtual router Name
Routing Protocol (Static/Dynamic)
15
Static Routes details
16 Address Object/Service Object details
Security/Access Policy details
17
NAT Policy details
Remote Logging and Remote
18
Management / Authentication details

Site-to-Site VPN Form


Parameter Site1
Location
Administrator's Name
Administrator's Contact
Administrator's Email
Vendor Case ID (Optional)
IKE-Phase1
Local IP
IKE Hash SHA256
IKE Encrypti AES256
IKE Aggress Auto
Renegotiate 86400secs
IKE Diffie-H 14
NAT traversal
IKE keep alive
Preshared key
Dead Peer De 5secs
IPSEC-Phase2
IPSEC Hash SHA256
IPSEC Encry AES256
IPSEC Perfec Group 14
Force key expiration
Renegotiate 3600secs
Renegotiate IPSEC SA Every (kb)
Encryption Domain (Interesting Traffic)
Network 1
Network 2
Network 3

Interface Details

Interface Interface Type

Zone Details

Name Type

Address Object Details

SR Name

Address Group details

SR Name

Service Object details


Sr. Name

Security Policies

Sr. Name

NAT Rules

Sr Name

Static Routes Details

Name Destination IP
Details
Pune STC
L&T Electrical & Automation, Switchgear Training Centre, T-
156/157, MIDC Bhosari, Pune- 411 026 Tel. : +91 20 2712
0037 / 0653
Sanjay Kale/ [email protected]/ 7598866274
PA820

9.1.5

1/1 - Primary Internet


1/2 - LAN
1/3 - DMZ (reserved)
1/4 - DMZ (reserved)
1/5 - Secondary Internet (if any)
WAN -
LAN -
DMZ -

Count -
Spoke Locations -
Default-VR
Static
Provide Static Route Template
As per Security Policy Template
Provide Security Policy Template
Provide Security Policy Template
Local Authentication and logging

Site-to-Site VPN Form


Site2

IKE-Phase1
IPSEC-Phase2

yption Domain (Interesting Traffic)

Management Profile Link State IP Address


Virtual Router
VLAN / Virtual Wire

Interfaces / Virtual Systems Zone Protection


User
Profile
ID
User
Enabled
ID Included
User IDNetworks
Excluded Networks

Type Address

Addresses
Protocol Destination Port

Source Zone Source Address


Destination
Destination
Zone Address
Application

Original Packet Source Zone Original Packet


OriginalDestination
Packet
Original
Destination
Zone
Original
PacketInterface
Source
PacketAddress
Destination Address

Next Hop interface Matric


Security ZoneFeatures Comment

Device
Device
ID Enabled
ID Included
Device IDNetworks
Excluded Networks
Service Action Profile

Original
Translated
Packet
Translated
Packet
ServiceSource
PacketTranslation
Destination Translation
Sr. No. Parameter

1 Location

2 Local Contact Person

3 Device Model
4 Network Architecture
5 OS Version
6 Management IP and mask
7 Hostname
8 DNS Server IP
9 NTP Server IP

10 Interface Configuration

11 Interface IP / Network

12 Zone Name & Mapping


IPSec Tunnel Details
13
(Provide filled VPN Template)
14 Virtual router Name
Routing Protocol (Static/Dynamic)
15
Static Routes details
16 Address Object/Service Object details
Security/Access Policy details
17
NAT Policy details
Remote Logging and Remote
18
Management / Authentication details

Site-to-Site VPN Form


Parameter Site1
Location
Administrator's Name
Administrator's Contact
Administrator's Email
Vendor Case ID (Optional)
IKE-Phase1
Local IP
IKE Hash SHA256
IKE Encrypti AES256
IKE Aggress Auto
Renegotiate 86400secs
IKE Diffie-H 14
NAT traversal
IKE keep alive
Preshared key
Dead Peer De 5secs
IPSEC-Phase2
IPSEC Hash SHA256
IPSEC Encry AES256
IPSEC Perfec Group 14
Force key expiration
Renegotiate 3600secs
Renegotiate IPSEC SA Every (kb)
Encryption Domain (Interesting Traffic)
Network 1
Network 2
Network 3

Interface Details

Interface Interface Type

Zone Details

Name Type

Address Object Details

SR Name

Address Group details

SR Name

Service Object details


Sr. Name

Security Policies

Sr. Name

NAT Rules

Sr Name

Static Routes Details

Name Destination IP
Details
Lucknow STC
L&T Electrical & Automation,Switchgear Training Centre, C-6 &
7, UPSIDC,P. O. Sarojininagar, Lucknow - 226 008, Tel. : +91
522 247 6015 / 97944 54455

Sabiha Ahmed / [email protected] / 9792902111

PA820

9.1.5

1/1 - Primary Internet


1/2 - LAN
1/3 - DMZ (reserved)
1/4 - DMZ (reserved)
1/5 - Secondary Internet (if any)
WAN -
LAN -
DMZ -

Count -
Spoke Locations -
Default-VR
Static
Provide Static Route Template
As per Security Policy Template
Provide Security Policy Template
Provide Security Policy Template
Local Authentication and logging

Site-to-Site VPN Form


Site2

IKE-Phase1
IPSEC-Phase2

yption Domain (Interesting Traffic)

Management Profile Link State IP Address


Virtual Router
VLAN / Virtual Wire

Interfaces / Virtual Systems Zone Protection


User
Profile
ID
User
Enabled
ID Included
User IDNetworks
Excluded Networks

Type Address

Addresses
Protocol Destination Port

Source Zone Source Address


Destination
Destination
Zone Address
Application

Original Packet Source Zone Original Packet


OriginalDestination
Packet
Original
Destination
Zone
Original
PacketInterface
Source
PacketAddress
Destination Address

Next Hop interface Matric


Security ZoneFeatures Comment

Device
Device
ID Enabled
ID Included
Device IDNetworks
Excluded Networks
Service Action Profile

Original
Translated
Packet
Translated
Packet
ServiceSource
PacketTranslation
Destination Translation
Sr. No. Parameter

1 Location

2 Local Contact Person

3 Device Model
4 Network Architecture
5 OS Version
6 Management IP and mask
7 Hostname
8 DNS Server IP
9 NTP Server IP

10 Interface Configuration

11 Interface IP / Network

12 Zone Name & Mapping


IPSec Tunnel Details
13
(Provide filled VPN Template)
14 Virtual router Name
Routing Protocol (Static/Dynamic)
15
Static Routes details
16 Address Object/Service Object details
Security/Access Policy details
17
NAT Policy details
Remote Logging and Remote
18
Management / Authentication details

Site-to-Site VPN Form


Parameter Site1
Location
Administrator's Name
Administrator's Contact
Administrator's Email
Vendor Case ID (Optional)
IKE-Phase1
Local IP
IKE Hash SHA256
IKE Encrypti AES256
IKE Aggress Auto
Renegotiate 86400secs
IKE Diffie-H 14
NAT traversal
IKE keep alive
Preshared key
Dead Peer De 5secs
IPSEC-Phase2
IPSEC Hash SHA256
IPSEC Encry AES256
IPSEC Perfec Group 14
Force key expiration
Renegotiate 3600secs
Renegotiate IPSEC SA Every (kb)
Encryption Domain (Interesting Traffic)
Network 1
Network 2
Network 3

Interface Details

Interface Interface Type

Zone Details

Name Type

Address Object Details

SR Name

Address Group details

SR Name

Service Object details


Sr. Name

Security Policies

Sr. Name

NAT Rules

Sr Name

Static Routes Details

Name Destination IP
Details
Coonoor STC
L&T Electrical & Automation, Switchgear Training Centre, Ooty-
Coonoor Main Road Yellanahali, P.O. The Nilgiris-643 243
Tel. : +91 423 251 7107

V Subramanian / [email protected] 9894426467

PA820

9.1.5

1/1 - Primary Internet


1/2 - LAN
1/3 - DMZ (reserved)
1/4 - DMZ (reserved)
1/5 - Secondary Internet (if any)
WAN -
LAN -
DMZ -

Count -
Spoke Locations -
Default-VR
Static
Provide Static Route Template
As per Security Policy Template
Provide Security Policy Template
Provide Security Policy Template
Local Authentication and logging

Site-to-Site VPN Form


Site2

IKE-Phase1
IPSEC-Phase2

yption Domain (Interesting Traffic)

Management Profile Link State IP Address


Virtual Router
VLAN / Virtual Wire

Interfaces / Virtual Systems Zone Protection


User
Profile
ID
User
Enabled
ID Included
User IDNetworks
Excluded Networks

Type Address

Addresses
Protocol Destination Port

Source Zone Source Address


Destination
Destination
Zone Address
Application

Original Packet Source Zone Original Packet


OriginalDestination
Packet
Original
Destination
Zone
Original
PacketInterface
Source
PacketAddress
Destination Address

Next Hop interface Matric


Security ZoneFeatures Comment

Device
Device
ID Enabled
ID Included
Device IDNetworks
Excluded Networks
Service Action Profile

Original
Translated
Packet
Translated
Packet
ServiceSource
PacketTranslation
Destination Translation
Sr. No. Parameter

1 Location

2 Local Contact Person

3 Device Model
4 Network Architecture
5 OS Version
6 Management IP and mask
7 Hostname
8 DNS Server IP
9 NTP Server IP

10 Interface Configuration

11 Interface IP / Network

12 Zone Name & Mapping


IPSec Tunnel Details
13
(Provide filled VPN Template)
14 Virtual router Name
Routing Protocol (Static/Dynamic)
15
Static Routes details
16 Address Object/Service Object details
Security/Access Policy details
17
NAT Policy details
Remote Logging and Remote
18
Management / Authentication details

Site-to-Site VPN Form


Parameter Site1
Location
Administrator's Name
Administrator's Contact
Administrator's Email
Vendor Case ID (Optional)
IKE-Phase1
Local IP
IKE Hash SHA256
IKE Encrypti AES256
IKE Aggress Auto
Renegotiate 86400secs
IKE Diffie-H 14
NAT traversal
IKE keep alive
Preshared key
Dead Peer De 5secs
IPSEC-Phase2
IPSEC Hash SHA256
IPSEC Encry AES256
IPSEC Perfec Group 14
Force key expiration
Renegotiate 3600secs
Renegotiate IPSEC SA Every (kb)
Encryption Domain (Interesting Traffic)
Network 1
Network 2
Network 3

Interface Details

Interface Interface Type

Zone Details

Name Type

Address Object Details

SR Name

Address Group details

SR Name

Service Object details


Sr. Name

Security Policies

Sr. Name

NAT Rules

Sr Name

Static Routes Details

Name Destination IP
Details
Kolkata STC
L&T Electrical & Automation, Switchgear Training Centre, 4th
Floor, 3B, Shakespeare Sarani, Kolkata - 700 071 Tel: +91 33
42005975 / 44085974 / 44085978

Vivek Ratnam / [email protected] / 96190 03098

PA820

9.1.5

1/1 - Primary Internet


1/2 - LAN
1/3 - DMZ (reserved)
1/4 - DMZ (reserved)
1/5 - Secondary Internet (if any)
WAN -
LAN -
DMZ -

Count -
Spoke Locations -
Default-VR
Static
Provide Static Route Template
As per Security Policy Template
Provide Security Policy Template
Provide Security Policy Template
Local Authentication and logging

Site-to-Site VPN Form


Site2

IKE-Phase1
IPSEC-Phase2

yption Domain (Interesting Traffic)

Management Profile Link State IP Address


Virtual Router
VLAN / Virtual Wire

Interfaces / Virtual Systems Zone Protection


User
Profile
ID
User
Enabled
ID Included
User IDNetworks
Excluded Networks

Type Address

Addresses
Protocol Destination Port

Source Zone Source Address


Destination
Destination
Zone Address
Application

Original Packet Source Zone Original Packet


OriginalDestination
Packet
Original
Destination
Zone
Original
PacketInterface
Source
PacketAddress
Destination Address

Next Hop interface Matric


Security ZoneFeatures Comment

Device
Device
ID Enabled
ID Included
Device IDNetworks
Excluded Networks
Service Action Profile

Original
Translated
Packet
Translated
Packet
ServiceSource
PacketTranslation
Destination Translation
Sr. No. Parameter

1 Location

2 Local Contact Person


3 Device Model
4 Network Architecture
5 OS Version
6 Management IP and mask
7 Hostname
8 DNS Server IP
9 NTP Server IP

10 Interface Configuration

11 Interface IP / Network

12 Zone Name & Mapping


IPSec Tunnel Details
13
(Provide filled VPN Template)
14 Virtual router Name
Routing Protocol (Static/Dynamic)
15
Static Routes details
16 Address Object/Service Object details
Security/Access Policy details
17
NAT Policy details
Remote Logging and Remote
18
Management / Authentication details

Site-to-Site VPN Form


Parameter Site1
Location
Administrator's Name
Administrator's Contact
Administrator's Email
Vendor Case ID (Optional)
IKE-Phase1
Local IP
IKE Hash SHA256
IKE Encrypti AES256
IKE Aggress Auto
Renegotiate 86400secs
IKE Diffie-H 14
NAT traversal
IKE keep alive
Preshared key
Dead Peer De 5secs
IPSEC-Phase2
IPSEC Hash SHA256
IPSEC Encry AES256
IPSEC Perfec Group 14
Force key expiration
Renegotiate 3600secs
Renegotiate IPSEC SA Every (kb)
Encryption Domain (Interesting Traffic)
Network 1
Network 2
Network 3

Interface Details

Interface Interface Type

Zone Details

Name Type

Address Object Details

SR Name

Address Group details

SR Name

Service Object details

Sr. Name
Security Policies

Sr. Name

NAT Rules

Sr Name

Static Routes Details

Name Destination IP
Details
New Delhi Sales
SEIPL, 1st Floor, A-25, Mohan Cooperative Industrial Area,
New Delhi - 110044

PA850

9.1.5

1/1 - Primary Internet


1/2 - LAN
1/3 - DMZ (reserved)
1/4 - DMZ (reserved)
1/5 - Secondary Internet (if any)
WAN -
LAN -
DMZ -

Count -
Spoke Locations -
Default-VR
Static
Provide Static Route Template
As per Security Policy Template
Provide Security Policy Template
Provide Security Policy Template
Local Authentication and logging

Site-to-Site VPN Form


Site2

IKE-Phase1
IPSEC-Phase2

yption Domain (Interesting Traffic)

Management Profile Link State IP Address


Virtual Router
VLAN / Virtual Wire

Interfaces / Virtual Systems Zone Protection


User
Profile
ID
User
Enabled
ID Included
User IDNetworks
Excluded Networks

Type Address

Addresses

Protocol Destination Port


Source Zone Source Address
Destination
Destination
Zone Address
Application

Original Packet Source Zone Original Packet


OriginalDestination
Packet
Original
Destination
Zone
Original
PacketInterface
Source
PacketAddress
Destination Address

Next Hop interface Matric


Security ZoneFeatures Comment

Device
Device
ID Enabled
ID Included
Device IDNetworks
Excluded Networks
Service Action Profile

Original
Translated
Packet
Translated
Packet
ServiceSource
PacketTranslation
Destination Translation
Sr. No. Parameter

1 Location

2 Local Contact Person

3 Device Model
4 Network Architecture
5 OS Version
6 Management IP and mask
7 Hostname
8 DNS Server IP
9 NTP Server IP

10 Interface Configuration

11 Interface IP / Network

12 Zone Name & Mapping


13 HA Mode
IPSec Tunnel Details
14
(Provide filled VPN Template)
15 Virtual router Name
Routing Protocol (Static/Dynamic)
16
Static Routes details
17 Address Object/Service Object details
Security/Access Policy details
18
NAT Policy details
Remote Logging and Remote
19
Management / Authentication details

Site-to-Site VPN Form


Parameter Site1
Location
Administrator's Name
Administrator's Contact
Administrator's Email
Vendor Case ID (Optional)
IKE-Phase1
Local IP
IKE Hash SHA256
IKE Encrypti AES256
IKE Aggress Auto
Renegotiate 86400secs
IKE Diffie-H 14
NAT traversal
IKE keep alive
Preshared key
Dead Peer De 5secs
IPSEC-Phase2
IPSEC Hash SHA256
IPSEC Encry AES256
IPSEC Perfec Group 14
Force key expiration
Renegotiate 3600secs
Renegotiate IPSEC SA Every (kb)
Encryption Domain (Interesting Traffic)
Network 1
Network 2
Network 3

Interface Details

Interface Interface Type

Zone Details

Name Type

Address Object Details

SR Name

Address Group details


SR Name

Service Object details

Sr. Name

Security Policies

Sr. Name

NAT Rules

Sr Name

Static Routes Details

Name Destination IP
Details
Saudi Arabia Factory
L&T Electrical and Automation Saudi Arabia Company Limited
Building 2555, 16th Street, Dammam 2nd Industrial City,
Dammam 34334, Kingdom of Saudi Arabia

Muhammed Fazil
[email protected] +966598546841
PA850 + PA850 HA

9.1.5

1/1 - Primary Internet


1/2 - LAN
1/3 - DMZ (reserved)
1/4 - DMZ (reserved)
1/5 - Secondary Internet (if any)
WAN -
LAN -
DMZ -
HA1 -
HA2 -

Active-Passive
Count -
Spoke Locations -
Default-VR
Static
Provide Static Route Template
As per Security Policy Template
Provide Security Policy Template
Provide Security Policy Template
Local Authentication and logging

Site-to-Site VPN Form


Site2

IKE-Phase1
IPSEC-Phase2

yption Domain (Interesting Traffic)

Management Profile Link State IP Address


Virtual Router
VLAN / Virtual Wire

Interfaces / Virtual Systems Zone Protection


User
Profile
ID
User
Enabled
ID Included
User IDNetworks
Excluded Networks

Type Address
Addresses

Protocol Destination Port

Source Zone Source Address


Destination
Destination
Zone Address
Application

Original Packet Source Zone Original Packet


OriginalDestination
Packet
Original
Destination
Zone
Original
PacketInterface
Source
PacketAddress
Destination Address

Next Hop interface Matric


Security ZoneFeatures Comment

Device
Device
ID Enabled
ID Included
Device IDNetworks
Excluded Networks
Service Action Profile

Original
Translated
Packet
Translated
Packet
ServiceSource
PacketTranslation
Destination Translation
Sr. No. Parameter

1 Location

2 Local Contact Person

3 Device Model
4 Network Architecture
5 OS Version
6 Management IP and mask
7 Hostname
8 DNS Server IP
9 NTP Server IP

10 Interface Configuration

11 Interface IP / Network

12 Zone Name & Mapping


13 HA Mode
IPSec Tunnel Details
14
(Provide filled VPN Template)
15 Virtual router Name
Routing Protocol (Static/Dynamic)
16
Static Routes details
17 Address Object/Service Object details
Security/Access Policy details
18
NAT Policy details
Remote Logging and Remote
19
Management / Authentication details

Site-to-Site VPN Form


Parameter Site1
Location
Administrator's Name
Administrator's Contact
Administrator's Email
Vendor Case ID (Optional)
IKE-Phase1
Local IP
IKE Hash SHA256
IKE Encrypti AES256
IKE Aggress Auto
Renegotiate 86400secs
IKE Diffie-H 14
NAT traversal
IKE keep alive
Preshared key
Dead Peer De 5secs
IPSEC-Phase2
IPSEC Hash SHA256
IPSEC Encry AES256
IPSEC Perfec Group 14
Force key expiration
Renegotiate 3600secs
Renegotiate IPSEC SA Every (kb)
Encryption Domain (Interesting Traffic)
Network 1
Network 2
Network 3

Interface Details

Interface Interface Type

Zone Details

Name Type

Address Object Details

SR Name

Address Group details

SR Name
Service Object details

Sr. Name

Security Policies

Sr. Name

NAT Rules

Sr Name

Static Routes Details

Name Destination IP
Details
Malaysia Factory
Sub Lot 24, Lot 16505, Jalan Keluli 1, Kawasan Perindustrian
Bukit Raja, Sekysen 7, 40000 Shah Alam, Selangor Darul
Ehsan, Malaysia.

Siva Kumar Muniandy/ +60333618286/ +60163329097/ [email protected]

PA3220 + PA3220 HA

9.1.5

1/1 - Primary Internet


1/2 - LAN
1/3 - DMZ (reserved)
1/4 - DMZ (reserved)
1/5 - Secondary Internet (if any)
WAN -
LAN -
DMZ -
HA1 -
HA2 -

Active-Passive
Count -
Spoke Locations -
Default-VR
Static
Provide Static Route Template
As per Security Policy Template
Provide Security Policy Template
Provide Security Policy Template
Local Authentication and logging

Site-to-Site VPN Form


Site2

IKE-Phase1
IPSEC-Phase2

yption Domain (Interesting Traffic)

Management Profile Link State IP Address


Virtual Router
VLAN / Virtual Wire

Interfaces / Virtual Systems Zone Protection


User
Profile
ID
User
Enabled
ID Included
User IDNetworks
Excluded Networks

Type Address

Addresses
Protocol Destination Port

Source Zone Source Address


Destination
Destination
Zone Address
Application

Original Packet Source Zone Original Packet


OriginalDestination
Packet
Original
Destination
Zone
Original
PacketInterface
Source
PacketAddress
Destination Address

Next Hop interface Matric


Security ZoneFeatures Comment

Device
Device
ID Enabled
ID Included
Device IDNetworks
Excluded Networks
Service Action Profile

Original
Translated
Packet
Translated
Packet
ServiceSource
PacketTranslation
Destination Translation
Sr. No. Parameter

1 Location

2 Local Contact Person

3 Device Model
4 Network Architecture
5 OS Version
6 Management IP and mask
7 Hostname
8 DNS Server IP
9 NTP Server IP

10 Interface Configuration

11 Interface IP / Network

12 Zone Name & Mapping


IPSec Tunnel Details
13
(Provide filled VPN Template)
14 Virtual router Name
Routing Protocol (Static/Dynamic)
15
Static Routes details
16 Address Object/Service Object details
Security/Access Policy details
17
NAT Policy details
Remote Logging and Remote
18
Management / Authentication details

Site-to-Site VPN Form


Parameter Site1
Location
Administrator's Name
Administrator's Contact
Administrator's Email
Vendor Case ID (Optional)
IKE-Phase1
Local IP
IKE Hash SHA256
IKE Encrypti AES256
IKE Aggress Auto
Renegotiate 86400secs
IKE Diffie-H 14
NAT traversal
IKE keep alive
Preshared key
Dead Peer De 5secs
IPSEC-Phase2
IPSEC Hash SHA256
IPSEC Encry AES256
IPSEC Perfec Group 14
Force key expiration
Renegotiate 3600secs
Renegotiate IPSEC SA Every (kb)
Encryption Domain (Interesting Traffic)
Network 1
Network 2
Network 3

Interface Details

Interface Interface Type

Zone Details

Name Type

Address Object Details

SR Name

Address Group details

SR Name

Service Object details


Sr. Name

Security Policies

Sr. Name

NAT Rules

Sr Name

Static Routes Details

Name Destination IP
Details
Malaysia Factory
Block A, Lot 21, Lorong Keluli 1C, Kawasan Perinduustrian
Bukit Raja, Sekysen 7, I-CITY 40000 Shah Alam, Selangor
Darul Ehsan, Malaysia.

Siva Kumar Muniandy/ +60333618286/ +60163329097/ [email protected]

PA820

9.1.5

1/1 - Primary Internet


1/2 - LAN
1/3 - DMZ (reserved)
1/4 - DMZ (reserved)
1/5 - Secondary Internet (if any)
WAN -
LAN -
DMZ -

Count -
Spoke Locations -
Default-VR
Static
Provide Static Route Template
As per Security Policy Template
Provide Security Policy Template
Provide Security Policy Template
Local Authentication and logging

Site-to-Site VPN Form


Site2

IKE-Phase1
IPSEC-Phase2

yption Domain (Interesting Traffic)

Management Profile Link State IP Address


Virtual Router
VLAN / Virtual Wire

Interfaces / Virtual Systems Zone Protection


User
Profile
ID
User
Enabled
ID Included
User IDNetworks
Excluded Networks

Type Address

Addresses
Protocol Destination Port

Source Zone Source Address


Destination
Destination
Zone Address
Application

Original Packet Source Zone Original Packet


OriginalDestination
Packet
Original
Destination
Zone
Original
PacketInterface
Source
PacketAddress
Destination Address

Next Hop interface Matric


Security ZoneFeatures Comment

Device
Device
ID Enabled
ID Included
Device IDNetworks
Excluded Networks
Service Action Profile

Original
Translated
Packet
Translated
Packet
ServiceSource
PacketTranslation
Destination Translation
Sr. No. Parameter

1 Location

2 Local Contact Person

3 Device Model
4 Network Architecture
5 OS Version
6 Management IP and mask
7 Hostname
8 DNS Server IP
9 NTP Server IP

10 Interface Configuration

11 Interface IP / Network

12 Zone Name & Mapping


13 HA Mode
IPSec Tunnel Details
14
(Provide filled VPN Template)
15 Virtual router Name
Routing Protocol (Static/Dynamic)
16
Static Routes details
17 Address Object/Service Object details
Security/Access Policy details
18
NAT Policy details
Remote Logging and Remote
19
Management / Authentication details

Site-to-Site VPN Form


Parameter Site1
Location
Administrator's Name
Administrator's Contact
Administrator's Email
Vendor Case ID (Optional)
IKE-Phase1
Local IP
IKE Hash SHA256
IKE Encrypti AES256
IKE Aggress Auto
Renegotiate 86400secs
IKE Diffie-H 14
NAT traversal
IKE keep alive
Preshared key
Dead Peer De 5secs
IPSEC-Phase2
IPSEC Hash SHA256
IPSEC Encry AES256
IPSEC Perfec Group 14
Force key expiration
Renegotiate 3600secs
Renegotiate IPSEC SA Every (kb)
Encryption Domain (Interesting Traffic)
Network 1
Network 2
Network 3

Interface Details

Interface Interface Type

Zone Details

Name Type

Address Object Details

SR Name

Address Group details

SR Name
Service Object details

Sr. Name

Security Policies

Sr. Name

NAT Rules

Sr Name

Static Routes Details

Name Destination IP
Details
Malaysia Factory
No.887, Jalan Subang 9, Taman Perindustrian Subang, 47500
Petaling Jaya, Selangor Darul Ehsan, Malaysia.

Siva Kumar Muniandy/ +60333618286/ +60163329097/ [email protected]

PA850 + PA850 HA

9.1.5

1/1 - Primary Internet


1/2 - LAN
1/3 - DMZ (reserved)
1/4 - DMZ (reserved)
1/5 - Secondary Internet (if any)
WAN -
LAN -
DMZ -
HA1 -
HA2 -

Active-Passive
Count -
Spoke Locations -
Default-VR
Static
Provide Static Route Template
As per Security Policy Template
Provide Security Policy Template
Provide Security Policy Template
Local Authentication and logging

Site-to-Site VPN Form


Site2

IKE-Phase1
IPSEC-Phase2

yption Domain (Interesting Traffic)

Management Profile Link State IP Address


Virtual Router
VLAN / Virtual Wire

Interfaces / Virtual Systems Zone Protection


User
Profile
ID
User
Enabled
ID Included
User IDNetworks
Excluded Networks

Type Address

Addresses
Protocol Destination Port

Source Zone Source Address


Destination
Destination
Zone Address
Application

Original Packet Source Zone Original Packet


OriginalDestination
Packet
Original
Destination
Zone
Original
PacketInterface
Source
PacketAddress
Destination Address

Next Hop interface Matric


Security ZoneFeatures Comment

Device
Device
ID Enabled
ID Included
Device IDNetworks
Excluded Networks
Service Action Profile

Original
Translated
Packet
Translated
Packet
ServiceSource
PacketTranslation
Destination Translation
Sr. No. Parameter

1 Location

2 Local Contact Person

3 Device Model
4 Network Architecture
5 OS Version
6 Management IP and mask
7 Hostname
8 DNS Server IP
9 NTP Server IP

10 Interface Configuration

11 Interface IP / Network

12 Zone Name & Mapping


IPSec Tunnel Details
13
(Provide filled VPN Template)
14 Virtual router Name
Routing Protocol (Static/Dynamic)
15
Static Routes details
16 Address Object/Service Object details
Security/Access Policy details
17
NAT Policy details
Remote Logging and Remote
18
Management / Authentication details

Site-to-Site VPN Form


Parameter Site1
Location
Administrator's Name
Administrator's Contact
Administrator's Email
Vendor Case ID (Optional)
IKE-Phase1
Local IP
IKE Hash SHA256
IKE Encrypti AES256
IKE Aggress Auto
Renegotiate 86400secs
IKE Diffie-H 14
NAT traversal
IKE keep alive
Preshared key
Dead Peer De 5secs
IPSEC-Phase2
IPSEC Hash SHA256
IPSEC Encry AES256
IPSEC Perfec Group 14
Force key expiration
Renegotiate 3600secs
Renegotiate IPSEC SA Every (kb)
Encryption Domain (Interesting Traffic)
Network 1
Network 2
Network 3

Interface Details

Interface Interface Type

Zone Details

Name Type

Address Object Details

SR Name

Address Group details

SR Name

Service Object details


Sr. Name

Security Policies

Sr. Name

NAT Rules

Sr Name

Static Routes Details

Name Destination IP
Details
Indonesia Factory
Blok F No 36, JL. Jababeka Raya Jababeka 1 Cikarang Bekasi
Indonesia 17350

Hadmoko / Mob : +62811907479 / [email protected]

PA820

9.1.5

1/1 - Primary Internet


1/2 - LAN
1/3 - DMZ (reserved)
1/4 - DMZ (reserved)
1/5 - Secondary Internet (if any)
WAN -
LAN -
DMZ -

Count -
Spoke Locations -
Default-VR
Static
Provide Static Route Template
As per Security Policy Template
Provide Security Policy Template
Provide Security Policy Template
Local Authentication and logging

Site-to-Site VPN Form


Site2

IKE-Phase1
IPSEC-Phase2

yption Domain (Interesting Traffic)

Management Profile Link State IP Address


Virtual Router
VLAN / Virtual Wire

Interfaces / Virtual Systems Zone Protection


User
Profile
ID
User
Enabled
ID Included
User IDNetworks
Excluded Networks

Type Address

Addresses
Protocol Destination Port

Source Zone Source Address


Destination
Destination
Zone Address
Application

Original Packet Source Zone Original Packet


OriginalDestination
Packet
Original
Destination
Zone
Original
PacketInterface
Source
PacketAddress
Destination Address

Next Hop interface Matric


Security ZoneFeatures Comment

Device
Device
ID Enabled
ID Included
Device IDNetworks
Excluded Networks
Service Action Profile

Original
Translated
Packet
Translated
Packet
ServiceSource
PacketTranslation
Destination Translation
Sr. No. Parameter

1 Location

2 Local Contact Person

3 Device Model
4 Network Architecture
5 OS Version
6 Management IP and mask
7 Hostname
8 DNS Server IP
9 NTP Server IP

10 Interface Configuration

11 Interface IP / Network

12 Zone Name & Mapping


IPSec Tunnel Details
13
(Provide filled VPN Template)
14 Virtual router Name
Routing Protocol (Static/Dynamic)
15
Static Routes details
16 Address Object/Service Object details
Security/Access Policy details
17
NAT Policy details
Remote Logging and Remote
18
Management / Authentication details

Site-to-Site VPN Form


Parameter Site1
Location
Administrator's Name
Administrator's Contact
Administrator's Email
Vendor Case ID (Optional)
IKE-Phase1
Local IP
IKE Hash SHA256
IKE Encrypti AES256
IKE Aggress Auto
Renegotiate 86400secs
IKE Diffie-H 14
NAT traversal
IKE keep alive
Preshared key
Dead Peer De 5secs
IPSEC-Phase2
IPSEC Hash SHA256
IPSEC Encry AES256
IPSEC Perfec Group 14
Force key expiration
Renegotiate 3600secs
Renegotiate IPSEC SA Every (kb)
Encryption Domain (Interesting Traffic)
Network 1
Network 2
Network 3

Interface Details

Interface Interface Type

Zone Details

Name Type

Address Object Details

SR Name

Address Group details

SR Name

Service Object details


Sr. Name

Security Policies

Sr. Name

NAT Rules

Sr Name

Static Routes Details

Name Destination IP
Details
Indonesia Sales
Tamco Indonesia, 21 Floor, JL. HR Rasuna Said Kav. 3-4
Kuningan, Jakarta - Indonesia 12950

Hadmoko / Mob : +62811907479 / [email protected]

PA820

9.1.5

1/1 - Primary Internet


1/2 - LAN
1/3 - DMZ (reserved)
1/4 - DMZ (reserved)
1/5 - Secondary Internet (if any)
WAN -
LAN -
DMZ -

Count -
Spoke Locations -
Default-VR
Static
Provide Static Route Template
As per Security Policy Template
Provide Security Policy Template
Provide Security Policy Template
Local Authentication and logging

Site-to-Site VPN Form


Site2

IKE-Phase1
IPSEC-Phase2

yption Domain (Interesting Traffic)

Management Profile Link State IP Address


Virtual Router
VLAN / Virtual Wire

Interfaces / Virtual Systems Zone Protection


User
Profile
ID
User
Enabled
ID Included
User IDNetworks
Excluded Networks

Type Address

Addresses
Protocol Destination Port

Source Zone Source Address


Destination
Destination
Zone Address
Application

Original Packet Source Zone Original Packet


OriginalDestination
Packet
Original
Destination
Zone
Original
PacketInterface
Source
PacketAddress
Destination Address

Next Hop interface Matric


Security ZoneFeatures Comment

Device
Device
ID Enabled
ID Included
Device IDNetworks
Excluded Networks
Service Action Profile

Original
Translated
Packet
Translated
Packet
ServiceSource
PacketTranslation
Destination Translation
Sr. No. Parameter

1 Location

2 Local Contact Person

3 Device Model
4 Network Architecture
5 OS Version
6 Management IP and mask
7 Hostname
8 DNS Server IP
9 NTP Server IP

10 Interface Configuration

11 Interface IP / Network

12 Zone Name & Mapping


13 HA Mode
IPSec Tunnel Details
14
(Provide filled VPN Template)
15 Virtual router Name
Routing Protocol (Static/Dynamic)
16
Static Routes details
17 Address Object/Service Object details
Security/Access Policy details
18
NAT Policy details
Remote Logging and Remote
19
Management / Authentication details

Site-to-Site VPN Form


Parameter Site1
Location
Administrator's Name
Administrator's Contact
Administrator's Email
Vendor Case ID (Optional)
IKE-Phase1
Local IP
IKE Hash SHA256
IKE Encrypti AES256
IKE Aggress Auto
Renegotiate 86400secs
IKE Diffie-H 14
NAT traversal
IKE keep alive
Preshared key
Dead Peer De 5secs
IPSEC-Phase2
IPSEC Hash SHA256
IPSEC Encry AES256
IPSEC Perfec Group 14
Force key expiration
Renegotiate 3600secs
Renegotiate IPSEC SA Every (kb)
Encryption Domain (Interesting Traffic)
Network 1
Network 2
Network 3

Interface Details

Interface Interface Type

Zone Details

Name Type

Address Object Details

SR Name

Address Group details

SR Name
Service Object details

Sr. Name

Security Policies

Sr. Name

NAT Rules

Sr Name

Static Routes Details

Name Destination IP
Details
UAE Factory
L&T Electrical & Automation FZE, Plot No. S30223,
P.O.Box: 262158, Jebel Ali Free Zone,
Dubai, U.A.E

[email protected]

PA850 + PA850 HA

9.1.5

1/1 - Primary Internet


1/2 - LAN
1/3 - DMZ (reserved)
1/4 - DMZ (reserved)
1/5 - Secondary Internet (if any)
WAN -
LAN -
DMZ -
HA1 -
HA2 -

Active-Passive
Count -
Spoke Locations -
Default-VR
Static
Provide Static Route Template
As per Security Policy Template
Provide Security Policy Template
Provide Security Policy Template
Local Authentication and logging

Site-to-Site VPN Form


Site2

IKE-Phase1
IPSEC-Phase2

yption Domain (Interesting Traffic)

Management Profile Link State IP Address


Virtual Router
VLAN / Virtual Wire

Interfaces / Virtual Systems Zone Protection


User
Profile
ID
User
Enabled
ID Included
User IDNetworks
Excluded Networks

Type Address

Addresses
Protocol Destination Port

Source Zone Source Address


Destination
Destination
Zone Address
Application

Original Packet Source Zone Original Packet


OriginalDestination
Packet
Original
Destination
Zone
Original
PacketInterface
Source
PacketAddress
Destination Address

Next Hop interface Matric


Security ZoneFeatures Comment

Device
Device
ID Enabled
ID Included
Device IDNetworks
Excluded Networks
Service Action Profile

Original
Translated
Packet
Translated
Packet
ServiceSource
PacketTranslation
Destination Translation
Sr. No. Parameter

1 Location

2 Local Contact Person

3 Device Model
4 Network Architecture
5 OS Version
6 Management IP and mask
7 Hostname
8 DNS Server IP
9 NTP Server IP

10 Interface Configuration

11 Interface IP / Network

12 Zone Name & Mapping


IPSec Tunnel Details
13
(Provide filled VPN Template)
14 Virtual router Name
Routing Protocol (Static/Dynamic)
15
Static Routes details
16 Address Object/Service Object details
Security/Access Policy details
17
NAT Policy details
Remote Logging and Remote
18
Management / Authentication details

Site-to-Site VPN Form


Parameter Site1
Location
Administrator's Name
Administrator's Contact
Administrator's Email
Vendor Case ID (Optional)
IKE-Phase1
Local IP
IKE Hash SHA256
IKE Encrypti AES256
IKE Aggress Auto
Renegotiate 86400secs
IKE Diffie-H 14
NAT traversal
IKE keep alive
Preshared key
Dead Peer De 5secs
IPSEC-Phase2
IPSEC Hash SHA256
IPSEC Encry AES256
IPSEC Perfec Group 14
Force key expiration
Renegotiate 3600secs
Renegotiate IPSEC SA Every (kb)
Encryption Domain (Interesting Traffic)
Network 1
Network 2
Network 3

Interface Details

Interface Interface Type

Zone Details

Name Type

Address Object Details

SR Name

Address Group details

SR Name

Service Object details


Sr. Name

Security Policies

Sr. Name

NAT Rules

Sr Name

Static Routes Details

Name Destination IP
Details
Qatar Factory
L&T Electrical & Automation Office Bldg. 209,
Ground Floor, C wing, Opp. Gulf Cinema,
C Ring Road, Doha, Qatar. PO Box: 15148

[email protected]

PA820

9.1.5

1/1 - Primary Internet


1/2 - LAN
1/3 - DMZ (reserved)
1/4 - DMZ (reserved)
1/5 - Secondary Internet (if any)
WAN -
LAN -
DMZ -

Count -
Spoke Locations -
Default-VR
Static
Provide Static Route Template
As per Security Policy Template
Provide Security Policy Template
Provide Security Policy Template
Local Authentication and logging

Site-to-Site VPN Form


Site2

IKE-Phase1
IPSEC-Phase2

yption Domain (Interesting Traffic)

Management Profile Link State IP Address


Virtual Router
VLAN / Virtual Wire

Interfaces / Virtual Systems Zone Protection


User
Profile
ID
User
Enabled
ID Included
User IDNetworks
Excluded Networks

Type Address

Addresses
Protocol Destination Port

Source Zone Source Address


Destination
Destination
Zone Address
Application

Original Packet Source Zone Original Packet


OriginalDestination
Packet
Original
Destination
Zone
Original
PacketInterface
Source
PacketAddress
Destination Address

Next Hop interface Matric


Security ZoneFeatures Comment

Device
Device
ID Enabled
ID Included
Device IDNetworks
Excluded Networks
Service Action Profile

Original
Translated
Packet
Translated
Packet
ServiceSource
PacketTranslation
Destination Translation

You might also like