18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 14: Configuring Virtual Private Networks<br />

Configuring VPN Security Associations<br />

444<br />

On the Identities sub-tab<br />

The Identities sub-tab is used to define unique identities for the following:<br />

• Firewall Identity is included in the response to the remote client and<br />

confirms to the client that it has established a VPN association with the<br />

correct endpoint.<br />

• Remote Identity is used to match a client identity with a particular security<br />

association; the <strong>Sidewinder</strong> <strong>G2</strong> can then use this information to determine<br />

the password the client should be using. The remote identity is optional for<br />

Fixed IP VPN associations because the <strong>Sidewinder</strong> <strong>G2</strong> can use the IP<br />

address to determine who the client is and thus what password the client<br />

should be using.<br />

1 In the Firewall Identity Type field, select the type <strong>of</strong> identity to use when<br />

identifying the <strong>Sidewinder</strong> <strong>G2</strong> to the remote client. Valid options are:<br />

• E-mail address<br />

• Fully Qualified Domain Name<br />

• IP Address<br />

Note: E-mail addresses are not recommended, as they are rarely used in the<br />

context <strong>of</strong> a security gateway.<br />

2 In the Value field, type the actual value used as the firewall identity. The<br />

value must be <strong>of</strong> the type specified in the Firewall Identity Type field (for<br />

example, if you selected IP Address in the Firewall Identity Type field, you<br />

must type an IP address in the Value field.<br />

3 Select the Gateway IP Address radio button if the <strong>Sidewinder</strong> <strong>G2</strong> should<br />

use the IP address <strong>of</strong> a Fixed IP client to determine what password the<br />

client should be using.<br />

4 Select the Remote Identities radio button if the <strong>Sidewinder</strong> <strong>G2</strong> should use a<br />

remote identity to determine the ID <strong>of</strong> the client. Valid identities for this<br />

association should be moved from the Available list to the Trusted list.<br />

5 [Optional] Click Remote Identities to go the Remote Identities window. This<br />

is useful if you want to use an identity that has yet to be created. When you<br />

add the identity and click Close, you will return to the Password<br />

Authentication Identities tab.<br />

6 Complete this tab by doing one <strong>of</strong> the following:<br />

• If you intend to change the Crypto or Advanced tab settings, go directly<br />

to the next tab without clicking Add or Close.<br />

• If you do not intend to change the Crypto or Advanced tab settings, click<br />

Add and then click Close. Click the Save icon.<br />

• If you do not want to save this Security Association entry, click Close<br />

without clicking Add.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!