192
Depending on the client and its configuration, a client may refuse
to connect if the server certificate does not include this attribute.
Signing certificate
Entering this screen, the certificate will be signed. By pressing the "Finish" button, the
new VPN server key will be installed.
Trusted VPN CA
To authenticate an IPSec VPN connection, SX-GATE verifies whether the certificate
presented by the peer has been issued by the trusted Certificate Authority (CA).
Currently the trusted CA is not SX-GATE's builtin CA. This is perfectly all right if an
external CA issues certificates for you. Otherwise you have the possibility to replace
it by SX-GATE's CA.
When changing the trusted CA, other VPN connections might no
longer work.
Although it is basically possible to have more than one trusted CA, on SX-GATE you
can specify only one to keep it more simple. If anyhow the certificates of the peers have
been issued by different CAs you have to make a decision which of them is to be the
trusted CA. For all other connections you have to stick to the other authentication mode
which requires the import of the peers' public keys. The respective configuration is not
supported by this wizard. Please change to the "Modules" menu instead. There you
can also set an external trusted CA.
CA based authentication requires that the SX-GATE VPN server
certificate has been issued by the trusted CA, too.
Please read on at
Client compatibility
MacOS and iPhone compatibility
The builtin L2TP clients of MacOS X and iPhone use a random source port instead of
port 1701 only. The IPSec tunnel will be extended if you enable this switch.