18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Authentication Summary<br />

Automatic key single<br />

certificate VPN<br />

Automatic key<br />

certificate authoritybased<br />

VPN<br />

Chapter 14: Configuring Virtual Private Networks<br />

<strong>Sidewinder</strong> <strong>G2</strong> VPN overview<br />

• authenticates using a self-signed public certificate - each VPN peer must first<br />

import the corresponding peer’s certificate<br />

• ideally used for a small number <strong>of</strong> remote clients<br />

• used with dynamic IP-assigned clients and gateways<br />

• each peer certificate requires its own <strong>Sidewinder</strong> <strong>G2</strong> security association<br />

• authenticates each VPN peer by using a certificate signed by a certificate authority<br />

trusted by the other peer<br />

• ideally suited for roving client VPN peers (such as those using laptop computers)<br />

• used with dynamic IP-assigned clients and gateways<br />

• single <strong>Sidewinder</strong> <strong>G2</strong> security association can be used to administer many VPN<br />

clients.<br />

General guidelines for selecting a VPN authentication type<br />

Here are some general guidelines to follow when you are deciding which type<br />

<strong>of</strong> VPN to use:<br />

• If the VPN peer is not a Secure Computing product, and all other types <strong>of</strong><br />

VPN methods do not work, try the manual key VPN.<br />

• For a small number <strong>of</strong> VPN peer clients with dynamically assigned IP<br />

addresses, the single certificate VPN is a cost-effective solution. A shared<br />

password VPN in conjunction with Extended Authentication is also an<br />

option.<br />

• If the VPN peer has a static IP address, the pre-shared password VPN is<br />

the easiest to configure. Extended Authentication would not be used in a<br />

gateway to gateway configuration as there is no one to provide the<br />

challenge/response.<br />

• If there is a large number <strong>of</strong> VPN peer clients with dynamically assigned-IP<br />

addresses (such as a traveling sales force), the CA-based VPN is <strong>of</strong>ten the<br />

easiest to configure and maintain. Another popular option is to use a preshared<br />

password VPN in conjunction with Extended Authentication.<br />

401

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!