06.03.2015 Views

iPECS SBG-1000 User Manual

iPECS SBG-1000 User Manual

iPECS SBG-1000 User Manual

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>iPECS</strong> <strong>SBG</strong>-<strong>1000</strong> <strong>User</strong> <strong>Manual</strong> (DATA Features)<br />

Figure 5.105 <strong>iPECS</strong> <strong>SBG</strong>-<strong>1000</strong> Connection Properties<br />

Click ‘Close’ to go back to the ‘Local Security Settings’ window (see Figure 5.88).<br />

6. Assigning the New IPSec Policy: In the ‘Local Security Settings’ window, right-click the<br />

‘<strong>iPECS</strong> <strong>SBG</strong>-<strong>1000</strong> Connection’ policy, and select ‘Assign’. A small green arrow will appear<br />

on the policy’s folder icon and its status under the ‘Policy Assigned’ column will change to<br />

‘Yes’.<br />

Figure 5.106 Local Security Settings<br />

5.4.1.5 IPSec Gateway-to-Gateway Connection Scenario<br />

Establishing an IPSec tunnel between Gateways A and B creates a transparent and secure<br />

network for clients from subnets A and B, who can communicate with each other as if they were<br />

inside the same network.<br />

This section describes how to create a gateway to gateway IPSec tunnel with the following<br />

authentication methods:<br />

• Pre-shared Secret – Developed by the VPN Consortium (VPNC). <strong>iPECS</strong> <strong>SBG</strong>-<strong>1000</strong>’s VPN<br />

feature is VPNC certified.<br />

• RSA Signature – A method using an RSA signature that is based on <strong>iPECS</strong> <strong>SBG</strong>-<strong>1000</strong>’s<br />

public key.<br />

• Peer Authentication of Certificates – A method using a Certificate Authority (CA).<br />

This section describes the network configuration of both gateways, followed by the IPSec tunnel<br />

setup methods. The configurations of both gateways are identical, except for their IP addresses<br />

and the use of these addresses when creating the tunnel—the default gateway address of each<br />

gateway should be the WAN IP address of the other gateway.<br />

Note: This section describes the configuration of Gateway A only. The same configuration<br />

must be performed on Gateway B, with the exceptions that appear in the note<br />

admonitions.<br />

106

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!