![Amit IWP87DAM-07151 User Manual Download Page 155](http://html1.mh-extra.com/html/amit/iwp87dam-07151/iwp87dam-07151_user-manual_2933418155.webp)
PoE
AP
Router
155
For
Network
‐
A
at
HQ
Following
tables
list
the
parameter
configuration
as
an
example
for
the
"Trusted
Certificate"
function
used
in
the
user
authentication
of
IPSec
VPN
tunnel
establishing,
as
shown
in
above
diagram.
The
configuration
example
must
be
combined
with
the
ones
in
"My
Certificate"
and
"Issue
Certificate"
sections
to
complete
the
setup
for
the
whole
user
scenario.
Configuration
Path
[Trusted
Certificate]
‐
[Trusted
Client
Certificate
List]
Command
Button
Import
Configuration
Path
[Trusted
Certificate]
‐
[Trusted
Client
Certificate
Import
from
a
File]
File
BranchCRT.crt
For
Network
‐
B
at
Branch
Office
Following
tables
list
the
parameter
configuration
as
an
example
for
the
"Trusted
Certificate"
function
used
in
the
user
authentication
of
IPSec
VPN
tunnel
establishing,
as
shown
in
above
diagram.
The
configuration
example
must
be
combined
with
the
ones
in
"My
Certificate"
and
"Issued
Certificate"
sections
to
complete
the
setup
for
the
whole
user
scenario.
Configuration
Path
[Trusted
Certificate]
‐
[Trusted
CA
Certificate
List]
Command
Button
Import
Configuration
Path
[Trusted
Certificate]
‐
[Trusted
CA
Certificate
Import
from
a
File]
File
HQRootCA.crt
Configuration
Path
[Trusted
Certificate]
‐
[Trusted
Client
Certificate
List]
Command
Button
Import
Configuration
Path
[Trusted
Certificate]
‐
[Trusted
Client
Certificate
Import
from
a
File]
File
HQCRT.crt
Scenario
Operation
Procedure
(same
as
the
one
described
in
"My
Certificate"
section)
In
above
diagram,
the
"Gateway
1"
is
the
gateway
of
Network
‐
A
in
headquarters
and
the
subnet
of
its
Intranet
is
10.0.76.0/24.
It
has
the
IP
address
of
10.0.76.2
for
LAN
interface
and
203.95.80.22
for
WAN
‐
1
interface.
The
"Gateway
2"
is
the
gateway
of
Network
‐
B
in
branch
office
and
the
subnet
of
its
Intranet
is
10.0.75.0/24.
It
has
the
IP
address
of
10.0.75.2
for
LAN
interface
and
118.18.81.33
for
WAN
‐
1
interface.
They
both
serve
as
the
NAT
security
gateways.
In
Gateway
2
import
the
certificates
of
the
root
CA
and
HQCRT
that
were
generated
and
signed
by