18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 14: Configuring Virtual Private Networks<br />

Example VPN Scenarios<br />

2 In the Admin Console, VPN Configuration > Client Address Pools, and<br />

then click New to create a new client address pool.<br />

Using a client address pool lets you define which local networks the clients<br />

can access. For this example, assume you want to permit access to the<br />

250.1.1.0 network but not the 192.168.182 network.<br />

Note: Your client s<strong>of</strong>tware must support this capability. SafeNet S<strong>of</strong>tRemote<br />

currently does not support this capability—it must be manually configured with<br />

information about the locally protected subnet.<br />

a Enter New Pool Name = SalesPool<br />

b Virtual Subnet = 10.1.1.0/24<br />

c Click New. In the Local Subnet field, enter 250.1.1.0/24 and then click<br />

Add.<br />

d Click Add to add the new pool.<br />

Note: The IP Address and Number <strong>of</strong> Bits in Netmask fields work in concert to<br />

determine the network portion <strong>of</strong> the addresses in the pool as well as the total<br />

number <strong>of</strong> addresses in the pool. The values shown here provide 254 possible<br />

addresses: 10.1.1.0–10.1.1.255. Modify these two values as appropriate for<br />

your situation.<br />

e On the Servers tab:<br />

If the client s<strong>of</strong>tware you are using supports this mode-config capability,<br />

specify your internal DNS and WINS servers here.<br />

f Click Add.<br />

g Click the Save icon to save your changes.<br />

3 In the Admin Console, VPN Configuration > Security Associations, and<br />

then click New to configure a new association.<br />

a On the General tab:<br />

• Name = Large_scale_sales<br />

• Encapsulation = Tunnel<br />

• Mode = Dynamic IP Restricted Client<br />

• Enabled = Yes<br />

• Burb = Virtual<br />

• Local IP = localhost<br />

• Client Address Pool = VPNPool<br />

b On the Authentication tab:<br />

• Authentication method = Certificate + Certificate Authority<br />

• Firewall Certificate = BizcoFW_by_CA (created in step 1B)<br />

• Certificate Authorities = BizcoCA (created in step 1A)<br />

• Remote Identities = Sales_force (created in step 1C)<br />

c On the Crypto tab: Order the algorithms to match that <strong>of</strong> the client.<br />

459

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!