general tab: select authentication method. I use IKE using preshared secret populate your shared secret password or phrase.
Proposals tab: generally leave these at default for most scenarios.
advanced tab: I leave at default except for check enable windows bios networking.
client tab: I set the 3 fields to Never, None, and Split Tunnels.
click ok and export the policy in rcf format setting a password on it if you wish.
Using the global vpn client import the rcf file into the client. do not use the wizard. it is not necessary if you have created and exported the policy in the TZ170. all you need to do is cancel out of the wizard and imort your premade policy into the vpn client.