
User Interface
R&S
®
GP-U/GP-E/GP-S/GP-T
106
User Manual 3646.3836.02 ─ 01
Field
Description
"ON"/"OFF"
A slider switch indicates whether VPN SSL is active ("ON") or inactive ("OFF").
By clicking the slider switch, you can toggle the state.
"Host certificate"
Select a host certificate that the gateprotect Firewall uses in all VPN SSL con-
nections.
"DNS"
Optional: Enter the DNS server which is to be used by clients in a Client-to-Site
connection for the time the connection is established.
"WINS"
Optional: Enter the WINS server which is to be used by clients in a Client-to-
Site connection for the time the connection is established.
"Timeout"
Specify the timeout of in seconds. The tunnel is disconnected if there is no traf-
fic until the timeout expires. The default setting is
0
, which means that the tun-
nel is maintained permanently.
"Log Level"
Define the log level. A log level of
5
is recommended for troubleshooting.
"Routes"
Enter routes for the VPN SSL tunnels that the clients or the remote end estab-
lishing the connection are to create. These routes then apply to all VPN SSL
connections.
Click "Add" to add the route to the list. You can edit or delete each single entry
in the list by clicking the appropriate button next to an entry. For further informa-
tion, see
Chapter 3.2, "Icons and Buttons"
Note:
If you edit an entry, a check mark appears on the right of the entry. Click
the check mark to apply your changes.
On the "Client-to-Site" tab:
Field
Description
"Protocol"
Select the protocol to be used by clicking the respective radio button.
"Port"
Specify the VPN SSL listening port number to be used for incoming connec-
tions.
Note:
The same port number must be specified in the client software.
"Address pool"
Specify the address range from which IP addresses are assigned to clients.
This address range must not overlap any of your local networks.
"Encryption algorithm"
From the drop-down list, select the encryption algorithm to be used in VPN SSL
C2S connections.
"Key renegotiation"
A VPN SSL connection renews the session key while the connection is estab-
lished to increase security. Specify this rekeying interval (in seconds).
"Compression"
Optional: Clear this checkbox to deactivate LZO (Lempel-Ziv-Oberhumer, a
lossless data compression algorithm) compression. This checkbox is selected
by default.
On the "Site-to-Site" tab:
Menu Reference