HiPath 3000/5000 in the LAN Network
Nur für den internen Gebrauch
A31003-H3590-S100-7-7620, 06/2012
13-38
HiPath 3000/5000 V9, Service documentation
h3h5_in_the_lan.fm
HG 1500 Board
13.6.9.4
Tunnel
HG 1500 V3.0 supports up to 256 tunnels per board.
A tunnel is a secure VPN connection to another VPN gateway or a VPN client. The HG 1500
establishes tunnels on level 3 based on IPsec.
Tunnel Configuration
For a tunnel to be set up, each terminal must be authenticated by the device at the other side.
Otherwise an LDAP server is used. The HG 1500 supports procedures that use public keys as
well as procedures based on shared secrets – similar to passwords.
For authentication using public keys, the HG 1500 can have CA (Certificate Authority) authen-
tication certificates assigned to it manually. However, it can also obtain CRLs (Certificate Re-
vocation Lists) automatically from an LDAP server.
For the authentication of VPN stations, the HG 1500 supports certificates according to X.509.
HG 1500 supports DSA and RSA as Public-Key algorithms.
HG 1500 as Certification Authority CA
As long as no other CA is available, the HG 1500 can, to a certain degree, act as a CA. It can
generate pairs of public and private keys, issue and sign relevant certificates, and save keys
and their corresponding certificates to files.
There is, however, no option to automatically transfer such certificates to clients; every such
transfer must be manually performed – with disks, for example.
Any subsequent certificate management, such as monitoring the period of validity or allocating
certificates to client data, must also be done manually.
The HG 1500 can create CRLs (Certificate Revocation Lists) of certificates that are considered
insecure and therefore are declared invalid before the end of the normal period of validity.
These lists must be distributed manually.
HG 1500 can work with certificates from external CAs. However, they can also issue certifi-
cates which can be used by other tunnel endpoints to authenticate themselves in a VPN. This
function is called “Lightweight CA” and requires a separate license.
Summary of Contents for HiPath 3000 Series
Page 1252: ......