18.07.2013 Views

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

The assumptions This VPN scenario assumes the following:<br />

Example VPN Scenarios<br />

A VPN connection between a <strong>Sidewinder</strong> and many clients<br />

A Certificate Authority-based VPN<br />

A single VPN association for all clients with a like security policy<br />

rather than one association per client<br />

The VPN association is terminated in a virtual burb<br />

The clients can have dynamic or static IP addresses<br />

VPN clients should have access to the 250.1.1.0 network but not<br />

the 192.168.182.0 network<br />

All clients make connections using a virtual IP address assigned<br />

from a client address pool<br />

All clients are using VPN client s<strong>of</strong>tware that supports mode-config<br />

Note: It is assumed in this scenario that the clients do not have access to the CA and must<br />

rely on the <strong>Sidewinder</strong> <strong>G2</strong> to create and distribute the necessary certificates and private<br />

keys.<br />

How it is done The following steps show the fields on the VPN menus that must be<br />

defined in order to create this VPN association. The basic idea is to:<br />

— Define the CA used with this VPN<br />

— Create a firewall certificate that is signed by the CA<br />

— Create one or more identities that define who is authorized to<br />

use this VPN<br />

— Create a client address pool<br />

— Create the VPN security association<br />

— Create the client certificates for each client<br />

— Provide certificate information and/or files to clients as<br />

necessary<br />

Tip: Some VPN client s<strong>of</strong>tware, such as SafeNet S<strong>of</strong>tRemote, allow users to self-enroll<br />

online to obtain their personal certificates, which can greatly reduce administrative effort.<br />

See the VPN Admin <strong>Guide</strong> for more details.<br />

Configuring Virtual Private Networks 13-73

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!