14.1.2.11.3 Connection with XAuth Client
291
All connections with dynamic IPs involved must use the
same key. Therefore it is configured along with the settings
of the ipsec interface and not with the connection specific
settings.
Remote ID (with PSK)
With preshared key authentication the peers identify each other using an IP address,
a hostname (FQDN) or an email address (USER@FQDN). To restrict this connection
to a client with a certain ID you can enter its ID here. If you don't know the peer's ID,
you can find it in the logs after an attempt of the peer to establish a VPN connection
with SX-GATE.
A client with dynamic IP which identifies itself by its IP must
provide an option to set a static ID. Otherwise it is not identifiable
by ID.
Remote ID (with CA based authentication)
Limit access to this connection to a single peer by entering the peer's ID. If you don't
know the peer's ID, you can find it in the logs after an attempt of the peer to establish
a VPN connection with SX-GATE. Certificate data (i.e. a Distinguished name, DN) is
expected as the peer's ID. It is not possible to enter an IP address or DNS name as
ID here.
This setting must be adjusted whenever the peer changes its
ID, e.g. because it received a new certificate and the new
certificate's DN differs from the old one.
Import public key
Here you can specify the public key of the client. If the client's certificate was issued
by the local SX-GATE CA, you can copy it from there. Otherwise you have to import
it from a file in PEM format.
You have to import the public key of the client itself and not the
public key of the issuing Certification Authority (CA).