204
If you change the trusted CA, connections which need to be
authenticated with the old CA can no longer be established.
A table gives you an overview of all available objects. If there are more than 10 entries,
a navigation bar will appear below the right bottom hand corner of the table where you
can page through the entries or open the table in fullscreen mode. Pick an entry by
clicking either its title or the pencil icon to enter the detail view.
Check VPN connection
Especially when configuring a SX-GATE in a branch office, uploading a setup archive
comes in handy. After confirmation of this screen an IPSec connection to the central
SX-GATE is configured, according to the data found in the archive. The connection
uses interface ipsec0 and is named after the peer's internet address as stated in the
setup archive. If necessary the ipsec0 interface will be created, the IPSec service will
be started and other configuration option will be changed as required.
If an IPSec connection with the same name exists, it will be
replaced.
Issue local VPN server certificate
With this function you can issue or renew the certificate of SX-GATE's own VPN server.
The new certificate will be signed by the SX-GATE CA and is valid for up to 6 years.
Issue new VPN server certificate
On this screen you have to enter the certificate subject.
CN
If SX-GATE has a static Internet IP address or a certain DNS name, you should supply
it here. Otherwise choose a name which is rather unambiguous.
Subject alternativ names
The certificate subject is a composition of all the data you entered before. You can add
an optional alternative name to the subject. Enter either the DNS name or the Internet
IP of SX-GATE.
It is not necessary to fill something in unless MacOS VPN clients
are used. MacOS clients expect the server certificate to contain
a subject alternative name. It must contain the server address
as configured in the MacOS client.