14.1.2.11.4 Connection with L2TP Client
295
any certificate signed by trusted CA
This is the commonly used and recommended way for certificate based
authentication. The client is accepted if it presents a certificate which has been
issued by a Certificate Authority (CA) which is trusted by SX-GATE. The trusted
CA is configured at "Modules > Network > Settings".
SX-GATE's VPN server certificate must have been issued
by the same CA or otherwise authentication will fail.
As the client's certificate is not installed on SX-GATE it can be renewed anytime
without local changes. The only requirement is that the new certificate also has
to be issued by the trusted CA.
If the CA certificate expires, all certificates will become
invalid. However a CA certificate is usually valid for a longer
period of time (e.g. 10 years).
Preshared key
Using this setting, the peer will be authenticated by a preshared key.
All connections with dynamic IPs involved must use the
same key. Therefore it is configured along with the settings
of the ipsec interface and not with the connection specific
settings.
Remote ID (with PSK)
With preshared key authentication the peers identify each other using an IP address,
a hostname (FQDN) or an email address (USER@FQDN). To restrict this connection
to a client with a certain ID you can enter its ID here. If you don't know the peer's ID,
you can find it in the logs after an attempt of the peer to establish a VPN connection
with SX-GATE.
A client with dynamic IP which identifies itself by its IP must
provide an option to set a static ID. Otherwise it is not identifiable
by ID.