background image

 

 
 
 
 
 
 
 

D-Link NetDefend VPN Client (DS-601/605) 

A quick installation guide

 

to

 

setting up the D-Link NetDefend VPN Client in a VPNC scenario 

 

 
 
 
 
 
 
 
 
 
These scenarios were developed by the VPN Consortium 

Scenario 1.  

Client-to-Gateway using pre-shared secrets

 

Typical client-to-gateway VPN using a preshared secret for authentication.   
Description how to configure the NCP Secure Entry Client for Windows. 

 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Document version 1.00 
Using 

D-Link NetDefend Client v1.0

 

 

 

Prepared by: 

   

NCP Engineering GmbH 

   

Dombuehler Strasse 2, 

   

90449 Nürnberg, Germany 

   

Phone:  +49-911-99.68.0 

   

Fax: +49-911-99.68.299 

Summary of Contents for DS-605 - VPN Client - PC

Page 1: ...ortium Scenario 1 Client to Gateway using pre shared secrets Typical client to gateway VPN using a preshared secret for authentication Description how to configure the NCP Secure Entry Client for Windows Document version 1 00 Using D Link NetDefend Client v1 0 Prepared by NCP Engineering GmbH Dombuehler Strasse 2 90449 Nürnberg Germany Phone 49 911 99 68 0 Fax 49 911 99 68 299 ...

Page 2: ...chantability or use for any particular purpose Furthermore NCP reserves the right to revise this publication and to make amendments to the content at any time without obligation to notify any person or entity of such revisions and changes Copyright This quick guide is the sole property of NCP and may not be copied for resale commercial distribution or translated to another language without the exp...

Page 3: ...e used for testing IPsec but is not needed for configuring Client A The IKE Phase 1 parameters used in Scenario 1 are Main mode TripleDES SHA 1 MODP group 2 1024 bits pre shared secret of hr5xb84l6aa9r6 SA lifetime of 28800 seconds eight hours with no kbytes rekeying The IKE Phase 2 parameters used in Scenario 1 are TripleDES SHA 1 ESP tunnel mode MODP group 2 1024 bits Perfect forward secrecy for...

Page 4: ...created and given the name Gateway B with Pre Shared Key Click Next figure 1 2 3 Configuration Assistant Link type Dial up configuration The VPN Client supports different media types the integrated dialer for example can be used to establish a connection to the ISP with a modem if available to the system prior to building the VPN Tunnel In this example select LAN over IP Click Next ...

Page 5: ... 2 5 Configuration Assistant Pre shared keys In this example a pre shared key or shared secret is used identical passwords on the IPSec communicating peers Enter in the given hr5xb84l6aa9r6 see section 1 1 and confirm this to ensure that it is correctly entered in The Finish button will not be available until the values have been correctly entered in and match ...

Page 6: ...iguration Profile Settings Open the Profile Settings to modify the parameters to define the specific IKE and IPSec proposals as specified in section 1 1 figure 1 3 2 Profile Settings Either double click on the profile that is going to be modified or select the profile and then click on Configure ...

Page 7: ...Settings Policy Lifetimes When automatic mode is selected for both the IKE Phase 1 and IPSec Phase 2 Policies the client will transmit a range of different commonly used proposals and the VPN Gateway can then select one to use for the connection However in this example although automatic mode works both the IKE and IPSec policies will be manually defined in accordance to section 1 1 so select Poli...

Page 8: ...n set to 8 hours 28800 seconds and the IPSec Policy SA lifetime is limited to 1 hour 3600 seconds Click OK to return to define the Proposals figure 1 3 6 Profile Settings IPSec General Settings Policy Editor Select the Policy Editor to define specific proposals to be used in this connection as lined out in section 1 1 ...

Page 9: ...mply select the parameters for this proposal Several proposals may be grouped together under the name but for the purpose of this example only one proposal is defined Select Preshared Key for the IKE mode Triple DES 168bit 3DES for the encryption algorithm to be used SHA 160bit SHA 1 for the authentication algorithm and finally DH Group 2 1024 Bit for the key exchange protocol Click OK to return t...

Page 10: ...Policy and click on New Entry to define the IPSec proposal Phase 2 parameters figure 1 3 10 Defining an IPSec Policy Simply select the parameters for this policy ESP tunnel mode Triple DES 168bit 3DES CBC for encryption algorithm and SHA SHA 1 160 Bit for the authentication code hash algorithm Click OK to continue ...

Page 11: ...fined Click on Close to save the proposals created and return to the Profile Settings IPSec General Settings dialog box figure 1 3 12 Profile Settings IPSec General Settings Select the newly defined IKE ISAKMP and IPSec Policies and click on Identities to move to the next dialog box ...

Page 12: ... IKE ID types can be used but are beyond the scope of this document please refer to the manual for more details Click on IP Address Assignment to continue figure 1 3 14 Profile Settings IP Address Assignment In this example the client is known to the VPN Gateway by a virtual IP address which has to be manually entered into the client Click on Remote Networks to move to the next dialog box ...

Page 13: ... segments that are to be reached This is used in the Phase 2 negotiation and often the cause for configuration mistakes In this scenario Gateway B s LAN segment 172 23 9 0 24 or netmask 255 255 255 0 is to be reached so that can be defined here Select the Firewall Settings to continue figure 1 3 16 Profile Settings Firewall Settings Click on OK to return to the main Profile Settings dialog box ...

Page 14: ...Version 0 90 Page 14 of 15 06 Sep 04 figure 1 3 17 Profile Settings Select OK to return to the monitor the graphical user interface of the VPN Client ...

Page 15: ...e established manually click on Connect to create the tunnel Then open a dos box and ping the internal network interface of the VPN Gateway to confirm the connection has been successfully established Depending on the VPN Gateway s configuration other hosts on the Gateway B s internal LAN can be reached figure 1 4 2 Command Prompt Ping response ...

Reviews: