In some
case it’s necessary to exclude a networks (or single IP address) in VPN tunnel.
It’s possible using the crypt.def
file, placed on the Security Management Server.
On the Security
Management Server there is no only one crypt.def
file, but there is one for each version of firewall we need to make the change.
To know the details please refer to the sk 98241.
First of
all create a backup file with the following command (in expert mode)
[Expert@HostName]#
cd $FWDIR/lib[Expert@HostName]# cp $FWDIR/lib/crypt.def $FWDIR/lib/crypt.def_BKP
Then open
the current “crypt.def” file
[Expert@HostName]# vi crypt.def
At the end of file you find this
string :