18.07.2013 Views

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Example VPN Scenarios<br />

All clients make connections using a virtual IP address assigned<br />

from a client address pool<br />

All clients use VPN client s<strong>of</strong>tware that supports mode-config<br />

Important: When determining your deployment method, consider what steps will you<br />

take to ensure the protection <strong>of</strong> your private key material. Allowing unauthorized access to<br />

your private key material could compromise your entire network.<br />

How it is done The following steps show the fields on the VPN menus that must be<br />

defined in order to create this VPN association. The basic idea is to:<br />

— Create a firewall certificate that identifies the <strong>Sidewinder</strong> <strong>G2</strong>.<br />

Export this certificate to each client.<br />

— Create a remote certificate that uniquely identifies each client.<br />

Export each certificate to the respective client.<br />

— Create a client address pool.<br />

— Create a VPN association for each client.<br />

1. In the Admin Console, select Services Configuration -> Certificate<br />

Management, and then enter the following information on each tab:<br />

a. On the Firewall Certificates tab, click New and create a firewall<br />

certificate by specify the following:<br />

Certificate Name = MyFirewall_cert<br />

Distinguished Name: CN=MyFirewall,O=bizco,C=US<br />

Submit to CA = Self Signed<br />

Signature Type = RSA<br />

Click Add.<br />

Click the Save icon.<br />

b. [Optional] On the Firewall Certificates tab, click Export and export<br />

the firewall certificate by specify the following:<br />

Destination = File<br />

Export Private Key to File: Click Browse and specify where you<br />

want to save the private key. The private key is <strong>of</strong>ten saved to an<br />

accessible location (portable storage device or protected<br />

network) for distribution to the client.<br />

Export Firewall Certificate to File: Click Browse and specify where<br />

you want to save the firewall certificate. The firewall certificate is<br />

<strong>of</strong>ten saved to an accessible location (portable storage device or<br />

protected network) for distribution to the client.<br />

Click OK.<br />

Configuring Virtual Private Networks 13-69

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!