18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 14: Configuring Virtual Private Networks<br />

Example VPN Scenarios<br />

• Click OK.<br />

f Repeat step 1e for each remote client. When you are finished you<br />

should have the firewall certificate as well as either the PKCS12formatted<br />

object or the certificate/key file pair for that client saved to a<br />

location accessible by the remote client (portable storage device or<br />

network)<br />

2 In the Admin Console, select VPN Configuration > Client Address Pools,<br />

and then click New to create a new client address pool.<br />

Using a client address pool lets you define which local networks the clients<br />

can access. For this example, assume you want to permit access to the<br />

250.1.1.0 network but not the 192.168.182 network.<br />

Note: Your client s<strong>of</strong>tware must support this capability. SafeNet S<strong>of</strong>tRemote<br />

currently does not support this capability—it must be manually configured with<br />

information about the locally protected subnet.<br />

a Enter New Pool Name = SalesPool<br />

b Virtual Subnet = 10.1.1.32/27<br />

c Click New. In the Local Subnet field, enter 250.1.1.0/24 and then click<br />

Add.<br />

d Click Add to add the new pool.<br />

Note: The Subnet and Number <strong>of</strong> Bits in Netmask fields work in concert to<br />

determine the network portion <strong>of</strong> the addresses in the pool as well as the<br />

total number <strong>of</strong> addresses in the pool. The values shown here provide 30<br />

possible addresses: 10.1.1.33 - 10.1.1.62. Modify these two values as<br />

appropriate for your situation. (For example, in this scenario you might<br />

alternatively specify IP Address = 10.1.1.16 and Netmask = 28, creating 14<br />

possible addresses: 10.1.1.17 - 10.1.1.30.)<br />

e On the Servers tab: If the client s<strong>of</strong>tware you are using supports this<br />

mode-config capability, specify your internal DNS and WINS servers<br />

here.<br />

f Click Add.<br />

3 In the Admin Console, select VPN Configuration > Security Associations,<br />

and then click New to configure a new association.<br />

a On the General tab:<br />

• Name = Sales_A<br />

• Encapsulation = Tunnel<br />

• Mode = Dynamic IP Restricted Client<br />

• Enabled = Yes<br />

• Burb = Virtual<br />

• Local IP = localhost<br />

• Client Address Pool = SalesPool<br />

455

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!