403
Providing remote access using VPN tunnels
Multicast traffic through gateway-to-gateway IPsec tunnels
Make a note of these two values. You will need them later to set up certificate generation on the
system.
2
To create a user profile (username.epf) based on the reference number and authorization code, use
the Entrust Profile creation utility, accessible from Start > Programs > Entrust > Create Profile.
3
When you are prompted, type a password.
This password must include letters and numbers and be at least 10 characters in length. Once
you’ve typed this information, the username.epf file is created.
Remember your user password. You will need to enter it on the security gateway when you run the
raptcert utility.
4
On the Entrust server, locate the entrust.ini and the username.epf file and copy both to the
security gateway.
To generate an Entrust certificate on the security gateway
1
Copy the entrust.ini file into the var/lib/sg directory.
2
Run the raptcert utility (in the var/lib/bin directory) and select
Create Entrust User Profile
from
the list of options.
3
In the File Name text box, type the name of the Entrust initialization file.
The default selection is entrust.ini. To accept the default file name, press
Enter
.
4
When prompted, type the reference number that was displayed in the Entrust Server window, and
then press
Enter
.
5
When prompted, type the authorization code that was displayed in the Entrust Server window, and
then press
Enter
.
6
When prompted, type the profile filename for saving keys, and then press
Enter
.
This is the .epf file that contains your certificate and private key. The raptcert utility creates the
.epf file in the var/lib/sg directory.
7
When prompted, type the password for encrypting your private key.
This value is used to encrypt your private key. This value must include letters and numbers and be
at least 10 characters in length.
Once these values are entered, raptcert.exe creates a public/private key pair locally on the system.
Then, the certificate is put in the .epf file you created in encrypted form.
8
To exit the raptcert utility, type o and press
Enter
.
9
Stop and then start the security gateway.
Check the log file to see that it reads “successfully logged into the ISAKMP engine with a
customized profile with certificate support.” When the IKE daemon starts running, it reads the .epf
and .ini files to log into the Entrust engine.
Related information
For further information related to this topic, see the following:
■
“Creating security gateway network entities for use in tunnels”
Multicast traffic through gateway-to-gateway IPsec tunnels
The security gateway provides a solution to pass multicast traffic over a network (such as the Internet)
through a gateway-to-gateway IPsec tunnel. Multiple VPN tunnels may exist between security
gateways. To build a tree-like routing structure for multicast packets and to prevent possible looping,
the appliance passes multicast traffic through tunnels that serve the security gateway only.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...