18.07.2013 Views

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Adding or modifying a<br />

client identification string<br />

Configuring<br />

Certificate<br />

Management<br />

Configuring Certificate Management<br />

To create or modify a client identifier, follow the steps below.<br />

1. Type the new client identifier in the Client ID field. You can type any <strong>of</strong><br />

the possible identifiers:<br />

Distinguished name<br />

E-mail address<br />

Domain name<br />

IP address<br />

XAUTH username<br />

Tip: The XAUTH username overrides all other client identification values. If the user<br />

will be using extended authentication, you should only add that user name for fixed<br />

IP mapping.<br />

2. Click Add to add the client ID to the list.<br />

3. To create additional client IDs, repeat step 1 and step 2 for each client ID.<br />

4. Click the Save icon.<br />

If you are using automatic key generation and intend to use<br />

certificates for authentication, you should configure the certificate<br />

and/or Certificate Authority (CA) server information before you set up<br />

the VPN. This eliminates the need to configure certificates and CAs<br />

during the VPN process. To configure certificate or CA information,<br />

follow these general steps.<br />

1. Review the section “Selecting a trusted source” on page 13-31 for<br />

details on certificates and CAs.<br />

2. Decide if you will use a public CA server, your private CA server, or selfsigned<br />

certificates generated by the <strong>Sidewinder</strong> <strong>G2</strong> (which can be used<br />

between two <strong>Sidewinder</strong> <strong>G2</strong>s or between a <strong>Sidewinder</strong> <strong>G2</strong> and a VPN<br />

client machine).<br />

3. If you are using a public or private CA server, go to “Configuring and<br />

displaying CA root certificates” on page 13-32. You may also want to<br />

add remote identities to be used in conjunction with a Certificate<br />

Authority policy. See “Configuring and displaying Remote Identities” on<br />

page 13-35.<br />

4. If you are using self-signed certificates, refer to the section titled<br />

“Configuring and displaying firewall certificates” on page 13-37.<br />

Configuring Virtual Private Networks 13-27

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!