© 2021 Cypress Solutions
Complete Manual: CTM-200 R2 (Revision 1.3)
45
Security
14.
Security
14.1
Remote Access Control
Remote access control can limit remote access to the CTM-200 embedded Web pages or command line consoles
(Telnet/SSH). Telnet and SSH connections are password protected with a configurable password.
14.2
Friends list
Block incoming packets from an IP address that is not defined as a “friend”. Eight Friends list IP addresses can
be defined.
14.3
LAN Friends
LAN Friends is used to control access to PC devices connected via the CTM-200 Ethernet ports. Up to 8 MAC
addresses can be allowed Ethernet access, all other devices will be denied packet forwarding and routing.
14.4
Radius
The CTM-200 LAN ports and Wi-Fi interface supports 802.1x Radius authentication servers.
15.
Networking
15.1
VPN
15.1.1
IPSec
The CTM-200 supports IPSec VPN communications.
The CTM-200 uses the KAME IPSec-tools: setkey tool to manipulate the Security Policy Database
(SPD) and Security Association Database (SAD), and the raccoon Internet Key Exchange (IKE)
daemon within the OpenCTM Linux 3.2 environment.
To successfully setup an IPSec communication tunnel between a CTM-200 and other VPN hardware a
variety of settings must be configured. A partial list required to begin to create a test environment is
below:
• server public IP
• server LAN IP subnet / netmask
• a pre-shared key for IPSec
• transport type : ESP / AH
• IKE Encryption and Diffie-Hellman Group eg. 3DES with Group 2 (1024-bit prime)
• encryption algorithm eg AES256, DES, 3DES
• hash algorithm eg. MD5, SHA1
15.1.2
VPNC
VPNC is a simplified IPSec/VPN client application that was developed as a Linux alternative to the Cisco
Easy VPN Client software for PCs. VPNC was initially developed to interoperate with Cisco VPN
Concentrators and PIX/IOS routers, but may work with other similar equipment.