Additional Mobile VPN Topics22 Mobile User VPNTerminating IPSec connectionsTo fully stop VPN connections, the Firebox must be restarted. Removing the IPSec policy does not stopcurrent connections.Global VPN settingsGlobal VPN settings on your Firebox apply to all manual BOVPN tunnels, managed tunnels, and MobileVPN tunnels. You can use these settings to:• Enable IPSec pass-through.• Clear or maintain the settings of packets with Type of Service (TOS) bits set.• Use an LDAP server to verify certificates.To change these settings, from Policy Manager, select VPN > VPN Settings. For more information onthese settings, see the Basic Configuration Setup chapter in the WatchGuard System Manager UserGuide.Seeing the number of Mobile VPN licensesTo see the number of Mobile VPN licenses that are installed, from Policy Manager, selectSetup > Feature Keys. From the Firebox Feature Keys dialog box, click Active Features. Scroll downto the value MUVPN_USERS and look at the number in the Capacity column. This is the number ofinstalled Mobile VPN licenses.Purchasing additional Mobile VPN licensesWatchGuard Mobile VPN with IPSec is an optional feature. Each Firebox X device includes a number ofMobile VPN licenses. You can purchase more licenses for Mobile VPN.Licenses are available through your local reseller or at:http://www.watchguard.com/salesAdding feature keysFor information on adding feature keys, see “Working with Feature Keys” in the WatchGuard SystemManager User Guide.Mobile VPN and VPN failoverYou can configure VPN tunnels to fail over to a backup endpoint if the primary endpoint becomesunavailable. For more information on VPN failover, see the WatchGuard System Manager User Guide.If VPN failover is configured and failover occurs, Mobile VPN sessions do not continue. You mustauthenticate your Mobile VPN client again to make a new Mobile VPN tunnel.To configure VPN failover for Mobile VPN tunnels, on the General tab of the Edit MUVPN ExtendedAuthentication Group dialog box, enter a backup WAN interface in the Backup field in the Firebox IPbox. You can specify only one backup interface for tunnels to fail over to, even if you have additionalWAN interfaces.