18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Figure 192: One VPN<br />

association per client<br />

VPN<br />

Client A<br />

VPN<br />

Client B<br />

The assumptions<br />

This VPN scenario assumes the following:<br />

Chapter 14: Configuring Virtual Private Networks<br />

Example VPN Scenarios<br />

• A VPN connection between a remote computer and the <strong>Sidewinder</strong> <strong>G2</strong><br />

• A self-signed firewall certificate that is generated by the <strong>Sidewinder</strong> <strong>G2</strong><br />

• One or more remote certificates that is generated by the <strong>Sidewinder</strong> <strong>G2</strong><br />

and distributed to the clients<br />

• One VPN association per client<br />

• Each VPN association is terminated in the Virtual burb<br />

• VPN clients should have access to the 250.1.1.0 network but not the<br />

192.168.182.0 network<br />

• All clients make connections using a virtual IP address assigned from a<br />

client address pool<br />

• All clients use VPN client s<strong>of</strong>tware that supports mode-config<br />

Important: When determining your deployment method, consider what steps will<br />

you take to ensure the protection <strong>of</strong> your private key material. Allowing<br />

unauthorized access to your private key material could compromise your entire<br />

network.<br />

How it is done<br />

Internet<br />

<strong>Sidewinder</strong> <strong>G2</strong><br />

200.1.1.1 Internet<br />

burb<br />

Trusted<br />

burb<br />

250.1.1.0/24<br />

Host<br />

Virtual<br />

burb<br />

fw.east.example.com<br />

Router<br />

192.168.182.0<br />

The following steps show the fields on the VPN menus that must be defined in<br />

order to create this VPN association. The basic idea is to:<br />

• Create a firewall certificate that identifies the <strong>Sidewinder</strong> <strong>G2</strong>. Export this<br />

certificate to each client.<br />

• Create a remote certificate that uniquely identifies each client. Export each<br />

certificate to the respective client.<br />

• Create a client address pool.<br />

• Create a VPN association for each client.<br />

Host<br />

453

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!