iPhones. Authorisation is verified either on the basis of a list or via a Radius Server. If using
a one time password (OTP), the password check can be carried out by a token server (e.g.
SecOVID from Kobil), which is installed behind the Radius Server. If a company's
headquarters is connected to several branches via IPSec, several peers can be configured.
A specific user can then use the IPSec tunnel over various peers depending on the assign-
ment of various profiles. This is useful, for example, if an employee works alternately in dif-
ferent branches, if each peer represents a branch and if the employee wishes to have on-
site access to the tunnel.
XAuth is carried out once IPSec IKE (Phase 1) has been completed successfully and be-
fore IKE (Phase 2) begins.
If XAuth is used together with IKE Config Mode, the transactions for XAuth are carried out
before the transactions for IKE Config Mode.
14.1.4.1 New
Choose the New button to create additional profiles.
The VPN->IPSec->XAUTH Profiles ->New menu consists of the following fields:
Fields in the Basic Parameters menu.
Field
Description
Description
Enter a description for this XAuth profile.
Role
Select the role of the gateway for XAuth authentication.
Possible values:
•
(default value): The gateway requires a proof of au-
thorisation.
•
%+
: The gateway provides proof of authorisation.
Mode
Only for Role =
Select how authentication is carried out.
Possible values:
•
?,-/
(default value): Authentication is carried out via a
Radius server. It is configured in the System
Management->Remote Authentication->RADIUS menu and
selected in the RADIUS Server Group ID field.
14 VPN
bintec elmeg GmbH
264
be.IP 4isdn