AlterPath ACS Command Reference Guide
135
Network
"Road Warrior" configuration
Think about the administrator that wants to access the ACS securely from wherever he
is, from his office desk, from his house, or from the hotel room. His IP address will not
be always the same, so, for IPsec purposes, he is a "Road Warrior." We refer to the
remote machines as Road Warriors. For purposes of IPsec, anyone with a dynamic IP
address is a Road Warrior.
Necessary Information
To set up a Road Warrior connection, you need some information about the system on
the other end. Connection descriptions use left and right to designate the two ends. We
adopt the convention that, from the Console Server's point of view, left=local and right
=remote. The Console Server administrator needs to know some things about each Road
Warrior:
•
The system's public key (for RSA only).
•
The ID that system uses in IPsec negotiation.
To get system's public key in a format suitable for insertion directly into the Console
Server's
ipsec.conf
file, issue this command on the warrior machine:
# /usr/local/sbin/ipsec showhostkey --right
The output should look like this (with the key shortened for easy reading):
rightrsasigkey=AQNe6hpbROGVES6uXeCxpnd88fdafpO0w5OT0s1LgR7/oUM...
The Road Warrior needs to know:
•
The Console Server's public key or the secret, and
•
The ID the Console Server uses in IPsec negotiation.
which can be generated by running:
# /usr/local/sbin/ipsec showhostkey --left
on the Console Server. Each warrior must also know the IP address of the Console
Server. This information should be provided in a convenient format, ready for insertion
in the warrior's
ipsec.conf
file. For example:
# left=1.2.3.4 [email protected] leftrsasigkey=0s1LgR7/oUM...
The Console Server administrator typically needs to generate this only once. The same
file can be given to all warriors.
Содержание AlterPath ACS
Страница 16: ...xvi Table of Contents...
Страница 29: ...13 This page has been left intentionally blank...
Страница 30: ...14 Preface...
Страница 68: ...52 Device Access...
Страница 86: ...70 Authentication Step 5 Saving changes To save the configuration run the command saveconf...
Страница 96: ...80 Authentication Save the configuration to flash 2 cli config savetoflash...
Страница 114: ...98 Authentication...
Страница 204: ...188 Administration To exit the CLI mode and return to ACS s shell issue the command cli quit...
Страница 268: ...252 Power Management with AlterPath PM Integration...
Страница 304: ...288 PCMCIA Cards Integration...
Страница 338: ...322 Profile Configuration...
Страница 364: ...348 Additional Features and Applications...
Страница 376: ...360 Appendix A New User Background Information...
Страница 406: ...390 Appendix C Cabling and Hardware Information This page has been left intentionally blank...
Страница 418: ...402 List of Tables...
Страница 420: ...404 List of Figures...