18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Adding or modifying<br />

a client<br />

identification string<br />

Configuring<br />

Certificate<br />

Management<br />

Chapter 14: Configuring Virtual Private Networks<br />

Configuring Certificate Management<br />

To create or modify a client identifier, follow the steps below.<br />

1 Type the new client identifier in the Client ID field. You can type any <strong>of</strong> the<br />

possible identifiers:<br />

• Distinguished name<br />

• E-mail address<br />

• Domain name<br />

• IP address<br />

• XAUTH username<br />

Tip: The XAUTH username overrides all other client identification values. If the<br />

user will be using extended authentication, you should only add that user name<br />

for fixed IP mapping.<br />

2 Click Add to add the client ID to the list.<br />

3 To create additional client IDs, repeat step 1 and step 2 for each client ID.<br />

4 Click the Save icon.<br />

If you are using automatic key generation and intend to use certificates for<br />

authentication, you should configure the certificate and/or Certificate Authority<br />

(CA) server information before you set up the VPN. This eliminates the need to<br />

configure certificates and CAs during the VPN process. To configure certificate<br />

or CA information, follow these general steps.<br />

1 Review the section “Selecting a trusted source” on page 419 for details on<br />

certificates and CAs.<br />

2 Decide if you will use a public CA server, your private CA server, or selfsigned<br />

certificates generated by the <strong>Sidewinder</strong> <strong>G2</strong> (which can be used<br />

between two <strong>Sidewinder</strong> <strong>G2</strong>s or between a <strong>Sidewinder</strong> <strong>G2</strong> and a VPN<br />

client machine).<br />

3 If you are using a public or private CA server, go to “Configuring and<br />

displaying CA root certificates” on page 420. You may also want to add<br />

remote identities to be used in conjunction with a Certificate Authority<br />

policy. See “Configuring and displaying Remote Identities” on page 422.<br />

4 If you are using self-signed certificates, refer to the section titled<br />

“Configuring and displaying firewall certificates” on page 424.<br />

5 If you are configuring a VPN between the <strong>Sidewinder</strong> <strong>G2</strong> and a machine<br />

running the client version <strong>of</strong> the <strong>Sidewinder</strong> <strong>G2</strong> VPN solution, and if you are<br />

not using a CA, you must create a remote certificate, export it, then import<br />

the certificate into the VPN client. Refer to the section titled “Exporting<br />

remote or firewall certificates” on page 435.<br />

415

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!