133
Key strength
Old systems like e.g. Windows XP before SP3 might only support keys with max. 2048
bit and an SHA1 hash.
Certificate request
Entering this screen, a certificate request will be generated on SX-GATE. You can sign
it now with the CA certificate.
Extended Key Usage: server authentication
Enable this option if the certificate is used by a server (e.g. web or VPN server).
Depending on the client and its configuration, a client may refuse
to connect if the server certificate does not include this attribute.
Extended Key Usage: client authentication
Enable this option if the certificate is used by a client (e.g. web browser or VPN client).
This may keep other clients from connecting, if this certificate is misused as a server
certificate.
Signing certificate
Entering this screen, the certificate will be signed and can be downloaded.
Create setup package
Windows IPSec-L2TP parameters
Internet IP or servername of SX-GATE
Please enter the DNS name or IP address the client will use to connect with SX-GATE.
Allow direct Internet access
If this option is disabled, there will be no direct Internet access for the client as soon
as the VPN connection is established. The client sets its default gateway to the VPN
tunnel. So any access to the Internet is routed via VPN and so via SX-GATE's firewall
and proxies. When the client disconnects, its default gateway is reset to the original
value, restoring direct internet access.
Enable this option and the client keeps its direct Internet connection. Only the relevant
IP addresses will be routed via VPN.
Connection-specific DNS suffix
You can optionally assign a connection-specific DNS suffix to the Windows client. So
the Windows client can e.g. resolve hosts on the LAN using their plain hostname.