18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 14: Configuring Virtual Private Networks<br />

Configuring the ISAKMP server<br />

• Trace—Logs all errors and informational messages. Also logs debug<br />

and function trace information.<br />

6 In the Available Authentication Methods field, select the authentication<br />

method(s) you want to be made available for VPN associations that use<br />

Extended Authentication. A check mark appears when an authentication<br />

button is selected. See “Extended Authentication for VPN” on page 399 for<br />

a detailed description <strong>of</strong> Extended Authentication.<br />

Note: You must configure an authentication method before it can be selected.<br />

See “Configuring authentication services” on page 284 for more information.<br />

7 If two or more authentication methods are selected, you should specify a<br />

default method from the Default drop-down list. If a default method is not<br />

selected, the first method selected in the list will be the default method.<br />

8 Click the Save icon in the toolbar to save your changes.<br />

Allowing access to the ISAKMP server<br />

An ISAKMP rule is required in order to allow access to and from the ISAKMP<br />

server. “Creating proxy rules” on page 222 describes how to define a proxy<br />

rule. The ISAKMP proxy rule must contain the following values:<br />

• Service Type = Server<br />

• Service = isakmp<br />

• Source Burb = the Internet burb<br />

• Destination Burb = the Internet burb<br />

• Source address = All Source Addresses (or addresses <strong>of</strong> remote VPN<br />

peers)<br />

• Destination address = a network object representing the IP address <strong>of</strong> the<br />

Internet burb, or a netgroup that contains a network object representing the<br />

IP address <strong>of</strong> the Internet burb<br />

This ISAKMP rule is implicitly bi-directional, meaning it enables ISAKMP traffic<br />

in both directions.<br />

Enabling/disabling the ISAKMP server<br />

Perform the following steps to enable or disable the ISAKMP server.<br />

1 In the Admin Console, select Services Configuration > Servers.<br />

2 Select isakmp from the list <strong>of</strong> server names.<br />

3 Click Enable or Disable.<br />

4 Click the Save icon in the toolbar.<br />

403

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!