![Black Box LS1016A User Manual Download Page 390](http://html.mh-extra.com/html/black-box/ls1016a/ls1016a_user-manual_2763435390.webp)
Appendix G - IPSEC
390
BLACK BOX
®
Advanced Console Server
•
If Network Address Translation (NAT) is applied between the two IPsec Gateways, this
breaks IPsec. IPsec authenticates packets on an end-to-end basis, to ensure they are not
altered en route. NAT rewrites packets as they go by.
In most situations, however, FreeS/WAN supports Road Warrior connections just fine.
Configuration
Before you Start
Set up and test networking
Before trying to get FreeS/WAN working, you should configure and test IP networking on the
Console Server and on the other end. IPsec cannot work without a working IP network
beneath it.
Many reported "FreeS/WAN problems” turn out to actually be problems with routing or fire-
walling. If any actual IPsec problems turn up, you often cannot even recognize them (much
less debug them) unless the underlying network is right.
Enabling IPsec
The IPsec is disabled by default in the Console Server family. To enable it you must edit the
file
/etc/inittab
and
/etc/config_files
and uncomment the lines regarding the IPsec. After per-
forming these changes you must save the configuration using the
saveconf
tool and reboot
the equipment.
Quick Start
This is a quick guide to set up two common configurations: VPN and Road Warrior. There are
three examples: a Road Warrior using RSA signature, a VPN using RSA signature and a VPN
using shared secret(s). It will assume the other end is also running the FreeS/Wan. If it is not
your case make the appropriate conversions for your IPsec software.
“Road Warrior” remote access
A common requirement is for connections between a Console Server and some set of remote
machines. For example, one administrator may want to access the Console Server from wher-