
VPN server
74
System Administrator’s Guide
To modify the password of an existing account, Select the account in the Account List
and then enter New Password and Confirm in the Delete or Change Password for the
Selected Account field.
To delete an existing account, Select the account in the Account List and then check
Delete in the Delete or Change Password for the Selected Account field.
If a requested change to a user account is successful, the PPTP VPN Setup screen is
shown with the change noted. An error is displayed if the change request is
unsuccessful.
Configuring remote VPN clients
The remote VPN clients can now be configured to securely access the local network.
You need to enter the a PPTP Account username and password that you added in the
previous section, and the IP address of the Shiva VPN Gateway PPTP VPN server.
The Shiva VPN Gateway PPTP VPN server IP address is displayed on the
Diagnostics page. This will generally be the same as the IP address of your main
Internet connection.
Note the current IP address of the Shiva VPN Gateway PPTP server. This address
may change if your ISP has not allocated you a static IP address. One solution to this
is to set up a Dynamic DNS service for use by your Shiva VPN Gateway (see Dynamic
DNS in the Network Connections section).
Ensure the remote VPN client computer has Internet connectivity. To create a VPN
connection across the Internet, you must set up two networking connections. One
connection is for ISP, and the other connection is for the VPN tunnel to your office
network.
Ensure that both the VPN and Dial Up Networking (DUN) software is installed on the
remote computer. If you are using Windows 95 or an older version of Windows 98 (first
edition), install the Microsoft DUN update (available on the Shiva VPN Gateway
Installation CD) and VPN Client update.
Your Shiva VPN Gateway's PPTP server will operate with the standard Windows
PPTP clients in all current versions of Windows.
L2TP server
The L2TP Server runs in a similar way to the PPTP Server. A range of IP addresses
is allocated, and then username and password pairs are created to allow users to log
on.
Note:
To increase security, L2TP VPN connections from Windows computers are
also run through an IPSec tunnel. This means an IPSec connection must be
configured and enabled as well as the L2TP server before Windows clients can
connect.
The default way for the IPSec connection to be authenticated is to use x.509/RSA
certificates. The Shiva VPN Gateway therefore needs to have IPSec configured with
both a CA and local certificate before connections can be established. The Windows
machine needs to have a copy of the CA certificate used to sign the Shiva VPN
Gateway local certificate, and similarly, the Shiva VPN Gateway needs a copy of the
CA of the Windows certificate.
Summary of Contents for SHIVA 1100
Page 38: ...QoS traffic shaping 38 System Administrator s Guide...
Page 44: ...DHCP relay 44 System Administrator s Guide...
Page 66: ...Access control 66 System Administrator s Guide...
Page 122: ...Technical Support 122 System Administrator s Guide...
Page 132: ...132 System Administrator s Guide...