5 - 116 WiNG 5.5 Access Point System Reference Guide
27. Select
OK
to save the updates made to the
Crypto Map Entry
screen. Selecting
Reset
reverts the screen to its last saved
setting.
28. Select
Remote VPN Server
.
Use this screen to define the server resources used to secure (authenticate) a remote VPN connection with a target peer.
IP Firewall Rules
Use the drop-down menu to select the
access list
(ACL) used to protect IPSec VPN
traffic. New access/deny rules can be defined for the crypto map by selecting the
Create
icon, or an existing set of firewall rules can be modified by selecting the
Edit
icon.
IPSec Transform Set
Select the transform set (encryption and hash algorithms) to apply to this crypto map
configuration.
Mode
Use the drop-down menu to define which mode (pull or push) is used to assign a virtual
IP. This setting is relevant for IKEv1 only, since IKEv2 always uses the configuration
payload in pull mode. The default setting is push.
Local End Point
Select this option to define an IP address as a local tunnel end-point address. This
setting represents an alternative to an interface IP address.
Perfect Forward Secrecy
(PFS)
PFS is key-establishment protocol, used to secure VPN communications. If one
encryption key is compromised, only data encrypted by that specific key is
compromised. For PFS to exist, the key used to protect data transmissions must not be
used to derive any additional keys. Options include
None
,
2
,
5
and
14
. The default
setting is None.
Lifetime (kB)
Select this option to define a connection volume lifetime (in kilobytes) for the duration
of an IPSec VPN security association. Once the set volume is exceeded, the association
is timed out. Use the spinner control to set the volume from 500 - 2,147,483,646
kilobytes.
Lifetime (seconds)
Select this option to define a lifetime (in seconds) for the duration of an IPSec VPN
security association. Once the set value is exceeded, the association is timed out. The
available range is from 120 - 86,400 seconds. The default setting is 120 seconds.
Protocol
Select the security protocol used with the VPN IPSec tunnel connection. SAs are
unidirectional, existing in each direction and established per security protocol. Options
include
ESP
and
AH
. The default setting is
ESP
.
Remote VPN Type
Define the remote VPN type as either
None
or
XAuth
. XAuth (extended authentication)
provides additional authentication validation by permitting an edge device to request
extended authentication information from an IPSec host. This forces the host to respond
with additional authentication credentials. The edge device respond with a failed or
passed message. The default setting is XAuth.
Manual Peer IP
Select this option to define the IP address of an additional encryption/decryption peer.
Time Out
Select this option to set the IPSec SA time out value. Use the textbox and the drop-down
list to configure the time out duration.
Enable NAT after IPSec
Select this option to enable NAT after IPSec. Enable this if there are NATted networks
behind VPN tunnels.
Summary of Contents for AP-7131 Series
Page 1: ...Motorola Solutions WiNG 5 5 ACCESS POINT SYSTEM REFERENCE GUIDE ...
Page 2: ......
Page 14: ...x WiNG 5 5 Access Point System Reference Guide ...
Page 22: ...8 WiNG 5 5 Access Point System Reference Guide ...
Page 26: ...1 4 WiNG 5 5 Access Point System Reference Guide ...
Page 74: ...3 36 WiNG 5 5 Access Point System Reference Guide ...
Page 428: ...6 2 WiNG 5 5 Access Point System Reference Guide Figure 6 1 Configuration Wireless menu ...
Page 528: ...6 102 WiNG 5 5 Access Point System Reference Guide ...
Page 610: ...8 40 WiNG 5 5 Access Point System Reference Guide ...
Page 615: ...Services Configuration 9 5 Figure 9 2 Captive Portal Policy screen Basic Configuration tab ...
Page 656: ...9 46 WiNG 5 5 Access Point System Reference Guide ...
Page 670: ...10 14 WiNG 5 5 Access Point System Reference Guide ...
Page 682: ...11 12 WiNG 5 5 Access Point System Reference Guide ...
Page 721: ...Operations 12 39 Figure 12 40 Certificate Management Import New Trustpoint screen ...
Page 738: ...12 56 WiNG 5 5 Access Point System Reference Guide ...
Page 890: ...A 2 WiNG 5 5 Access Point System Reference Guide ...
Page 952: ...B 62 WiNG 5 5 Access Point System Reference Guide ...
Page 953: ......