Page 161 of 226
Version: 3.3.5
– DR05 – 23.03.2017
Authentication
Select the
Authentication process
via the drop-down field.
Authentication by peer certificate:
The certificates can be signed by different CAs. A personal certkey (.p12 file) must be imported into each
router. Each router must also have a copy of the respective peer certificate, naturally WITHOUT the key (.crt file).
Own Certificate
:
Select the router
’s personal certificate via the drop-down field.
Local ID:
This ID is normally assigned by the certificate. This field can be left blank.
Peer Certificate
:
Select the peer certificate here.
Peer ID
:
This ID can only be assigned by the certificate if
Authentication by peer certificate
was selected. The field can be
left blank in this case. If, however,
Authentication by certificate from CA
was selected, you must specify the peer
ID (
in case you want to establish the connection
).
This ID is selected when the certificate is created (see the section
Creating certificates and revocation lists using
under the tab Subject). It is the certificate subject and must be entered as follows:
/C=country/ST=state/L=city/O=organization/OU=department/CN=certificate_name/E=email_address
If some fields on the
Subject
tab were left blank when the certificate was created, the corresponding entries must be
Creating certificates and revocation lists using XCA
Peer Certificate
:
Only if
Authentication by peer certificate
was selected. Select the corresponding certificate via the drop-down
field.
Authentication by certificate from CA:
The root certificate (certificate authority, CA for short) and a personal certificate including key (.p12 file) must be im-
ported into the router for this. (See the section System
– Certificates). The remote station must have the same root
certificate and a certificate signed by the CA including key.
PSK
:
Both keys must be known before data can be exchanged between the client and router. The longer the keys,
the more secure the connection.
Only one
key can be specified. Even if there are several PSK connections entered, the key for the
FIRST
connec-
tion is universally valid.
Local ID:
Assign a name for your router here. This name must be communicated to the peer
.
Peer ID:
Enter the name of the peer here.
X.509:
You can choose between two authentication processes via the drop-down field: