c.
Add the Root Certificate to use.
4.
The IPsec client software will need to be appropriately configured with the certificates and
remote IP addresses. As already mentioned above, many third party IPsec client products are
available and this manual will not focus on any one of these clients.
The step to set up user authentication is optional since this is additional security to certificates.
Also review Section 9.6, “CA Server Access”, which describes important considerations for
certificate validation.
9.2.5. L2TP Roaming Clients with Pre-Shared Keys
Due to the inbuilt L2TP client in Microsoft Windows, L2TP is a popular choice for roaming client
VPN scenarios. L2TP is usually encapsulated in IPsec to provide encryption with IPsec running in
transport mode instead of tunnel mode. The steps for L2TP over IPsec setup are:
1.
Create an IP object (let's call it l2tp_pool) which defines the range of IP addresses which can be
handed out to clients. The range chosen could be of two types:
•
A range taken from the internal network to which clients will connect. If the internal
network is 192.168.0.0/24 then we might use the address range 192.168.0.10 to
192.168.0.20. The danger here is that an IP address might be accidentally used on the
internal network and handed out to a client.
•
Use a new address range that is totally different to any internal network. This prevents any
chance of an address in the range also being used on the internal network.
2.
Define two other IP objects:
•
ip_ext which is the external public IP address through which clients connect (let's assume
this is on the ext interface).
•
ip_int which is the internal IP address of the interface to which the internal network is
connected (let's call this interface int).
3.
Define a Pre-shared Key for the IPsec tunnel.
4.
Define an IPsec Tunnel object (let's call this object ipsec_tunnel) with the following
parameters:
•
Set Local Network to ip_ext (specify all-nets instead if NetDefendOS is behind a NATing
device).
•
Set Remote Network to all-nets.
•
Set Remote Endpoint to none.
•
For Authentication select the Pre-shared Key object defined in the first step.
•
Set Encapsulation Mode to Transport.
•
Select the IKE and IPsec algorithm proposal lists to be used.
•
Enable the routing option Dynamically add route to the remote network when tunnel
established. If all-nets is the destination network, the option Add route for remote network
should be disabled.
5.
Define an PPTP/L2TP Server object (let's call this object l2tp_tunnel) with the following
parameters:
9.2.5. L2TP Roaming Clients with
Pre-Shared Keys
Chapter 9. VPN
328
Содержание 800 - DFL 800 - Security Appliance
Страница 24: ...1 3 NetDefendOS State Engine Packet Flow Chapter 1 NetDefendOS Overview 24 ...
Страница 69: ...2 6 4 Restore to Factory Defaults Chapter 2 Management and Maintenance 69 ...
Страница 121: ...3 9 DNS Chapter 3 Fundamentals 121 ...
Страница 166: ...interfaces without an overriding IGMP Setting Default 1 000 4 6 4 Advanced IGMP Settings Chapter 4 Routing 166 ...
Страница 181: ...4 7 5 Advanced Settings for Transparent Mode Chapter 4 Routing 181 ...
Страница 192: ...5 5 IP Pools Chapter 5 DHCP Services 192 ...
Страница 282: ...6 7 Blacklisting Hosts and Networks Chapter 6 Security Mechanisms 282 ...
Страница 300: ...mechanism 7 3 7 SAT and FwdFast Rules Chapter 7 Address Translation 300 ...
Страница 301: ...7 3 7 SAT and FwdFast Rules Chapter 7 Address Translation 301 ...
Страница 303: ... Changed on a regular basis such as every three months 8 1 Overview Chapter 8 User Authentication 303 ...
Страница 318: ...8 3 Customizing HTML Pages Chapter 8 User Authentication 318 ...
Страница 322: ...ALG 9 1 5 The TLS Alternative for VPN Chapter 9 VPN 322 ...
Страница 377: ...Management Interface Failure with VPN Chapter 9 VPN 377 ...
Страница 408: ...10 4 6 SLB_SAT Rules Chapter 10 Traffic Management 408 ...
Страница 419: ...11 5 HA Advanced Settings Chapter 11 High Availability 419 ...
Страница 426: ...12 3 5 Limitations Chapter 12 ZoneDefense 426 ...
Страница 449: ...13 9 Miscellaneous Settings Chapter 13 Advanced Settings 449 ...