Virtual Private Networks (VPN)
IPsec
IX10 User Guide
261
n
SCEP certificates
: Uses Simple Certificate Enrollment Protocol (SCEP) to download
a private key, certificates, and an optional Certificate Revocation List (CRL) to the
IX10 device from a SCEP server.
You must create the SCEP client prior to configuring the IPsec tunnel. See
a Simple Certificate Enrollment Protocol client
for instructions.
i. For
SCEP Client
, select the SCEP client.
n
X.509 certificate
: Uses private key and X.509 certificates to authenticate with the
remote peer.
i. For
Private key
, paste the device's private RSA key in PEM format.
ii. Type the
Private key passphrase
that is used to decrypt the private key.
Leave blank if the private key is not encrypted.
iii. For
Certificate
, paste the local X.509 certificate in PEM format.
iv. For Peer verification, select either:
l
Peer certificate
: For
Peer certificate
, paste the peer's X.509 certificate in
PEM format.
l
Certificate Authority
: For
Certificate Authority chain
, paste the
Certificate Authority (CA) certificates. These must include all peer
certificates in the chain up to the root CA certificate, in PEM format.
15. (Optional) For
Management Priority
, set the management priority for this IPsec tunnel. A
tunnel that is up and has the highest priority will be used for central management and direct
device access.
16. (Optional) To configure the device to connect to its remote peer as an XAUTH client:
a. Click to expand
XAUTH client
.
b. Click
Enable
.
c. Type the
Username
and
Password
that the device will use to authenticate as an
XAUTH client with the peer.
17. (Optional) Click
Enable MODECFG client
to receive configuration information, such as the
private IP address, from the remote peer.
18. Click to expand
Local endpoint
.
a. For
Type
, select either:
n
Default route
: Uses the same network interface as the default route.
n
Interface
: Select the
Interface
to be used as the local endpoint.
b. Click to expand
ID
.
i. Select the ID type:
n
Auto
: The ID will be automatically determined from the value of the tunnels
endpoints.
Содержание IX10
Страница 1: ...IX10 User Guide User Guide Firmware version 22 5 ...
Страница 444: ...Services Simple Network Management Protocol SNMP IX10 User Guide 444 The SNMP page is displayed 4 Click Download ...
Страница 740: ...Monitoring This chapter contains the following topics intelliFlow 741 Configure NetFlow Probe 748 IX10 User Guide 740 ...
Страница 823: ...Command line interface Execute a command from the web interface IX10 User Guide 823 The Admin CLI prompt appears ...
Страница 849: ...Command line interface Command line reference IX10 User Guide 849 Parameters None ...
Страница 858: ...Command line interface Command line reference IX10 User Guide 858 reboot Reboot the system Parameters None ...