18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 14: Configuring Virtual Private Networks<br />

Example VPN Scenarios<br />

458<br />

• Provide certificate information and/or files to clients as necessary<br />

Tip: Some VPN client s<strong>of</strong>tware, such as SafeNet S<strong>of</strong>tRemote, allow users to selfenroll<br />

online to obtain their personal certificates, which can greatly reduce<br />

administrative effort. See the VPN Admin <strong>Guide</strong> for more details.<br />

1 In the Admin Console, select Services Configuration > Certificate<br />

Management, and then enter the following information on each tab.<br />

a On the Certificate Authorities tab, click New and create a CA by<br />

specifying the following:<br />

• CA Name = BizcoCA<br />

• Type = SCEP (or whatever value is appropriate)<br />

• URL = http://10.18.128.8<br />

• Click Add.<br />

• Click the Save icon to save your changes.<br />

• Click Get CA Cert (Retrieves the CA Cert from the URL address.)<br />

• Click Get CRL (Retrieves the Certificate Revocation List for this CA.)<br />

b On the Firewall Certificates tab, click New and create a firewall<br />

certificate by specifying the following:<br />

• Certificate Name = BizcoFW_by_CA<br />

• Distinguished Name: CN=BizcoFW_by_CA,O=Bizco,C=US<br />

• Submit to CA = BizcoCA<br />

• Signature Type = RSA<br />

• Click Add.<br />

• Click the Save icon to save your changes.<br />

At this point the Status field for this certificate will be PENDING. This is<br />

because the request has been sent to the CA but the certificate has yet<br />

to be created. The status will remain PENDING until the CA administrator<br />

approves your request.<br />

• Click Query. This queries the CA to see if the certificate is approved.<br />

If yes, the Status field will change to SIGNED and the certificate is<br />

imported.<br />

Note: The <strong>Sidewinder</strong> <strong>G2</strong> automatically queries the CA every 15 minutes to<br />

see if the request has been accepted. If the request has been accepted, the<br />

<strong>Sidewinder</strong> <strong>G2</strong> will retrieve the resulting certificate.<br />

c On the Remote Identities tab, click New and create one or more<br />

identities that define who is authorized to use this VPN.<br />

• Identity Name = Sales_force<br />

• Distinguished Name: CN=*,OU=sales,O=bizco,C=us<br />

• Click Add.<br />

• Click Close.<br />

• Click the Save icon to save your changes.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!