18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 14: Configuring Virtual Private Networks<br />

Configuring Certificate Management<br />

Adding or modifying<br />

a Remote Identity<br />

424<br />

The Create New Remote Identity window enables you to add a new remote<br />

identity. You can also modify an existing remote identity within the Remote<br />

Identities tab. To add or modify a remote identity, follow the steps below.<br />

Tip: An asterisk can be used as a wildcard when defining the fields on this window.<br />

(Other special characters are not allowed.) For example; *, O=bizco, C=us<br />

represents all users at Bizco.<br />

1 In the Identity Name field, type a name for this Remote Identity.<br />

2 In the Distinguished Name field, create a distinguished name. See<br />

“Understanding Distinguished Name syntax” on page 416 for information on<br />

the format that should be used.<br />

Note: The order <strong>of</strong> the specified distinguished name fields must match the<br />

order listed in the certificate.<br />

3 [Optional] In the E-Mail Address field, enter the e-mail address(es) to which<br />

you want to restrict access. Enter one e-mail address per identity or use a<br />

wildcard to indicate all e-mail addresses, such as *@example.com.<br />

4 [Optional] In the Domain Name field, type the specific domain name to<br />

which you want to restrict access. Enter one domain name per identity or<br />

use a wildcard to indicate all domain names, such as *.example.com.<br />

5 [Optional] In the IP Address field, type the unique IP address or group <strong>of</strong> IP<br />

addresses to which you want to restrict access. For example: 182.19.0.0/16<br />

indicates that only users with IP addresses beginning with 182.19 (as<br />

contained in the certificate) will be authorized to use the VPN.<br />

6 Click Add to add the identity to the Identities list.<br />

7 To define additional remote IDs, repeat step 1–step 6.<br />

8 Click the Save icon.<br />

Configuring and displaying firewall certificates<br />

A firewall certificate is used to identify the <strong>Sidewinder</strong> <strong>G2</strong> to a potential peer in<br />

a VPN connection. When creating a certificate for the <strong>Sidewinder</strong> <strong>G2</strong>, you have<br />

the option to submit the certificate to a CA for validation, or have the<br />

<strong>Sidewinder</strong> <strong>G2</strong> generate a self-signed certificate. You should create these<br />

certificates before you begin configuring a VPN.<br />

In the Admin Console, select Services Configuration > Certificate<br />

Management, then select the Firewall Certificates tab. The following window<br />

appears.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!