The present invention provides device configuration and policy
configuration data to network devices over a public network, e.g., the
internet. A secure communication link is first established over the
public network to the network device. Next, policy and configuration
information is downloaded to the network device using that secure
communication link. In one embodiment, the communication link is an IPSec
tunnel. In particular, the network policy may include a virtual private
network (VPN) policy. The invention addresses the secure downloading of
configuration and policy information, which has not been an issue in
prior art devices where there was an ability to provide such information
internally to a network, without the need to go over the internet.