Quadro4Li Manual II: Administrator's Guide
Administrator’s Menus
Quadro4Li; (SW Version 5.3.x)
115
The
Peer type
drop down list is used to choose the remote
machine type for the IPSec Connection to be established. If the
list does not include the required type of machine, choose
Other
.
The
VPN Network Topology
drop down list allows you to select
the location of the peers participating to the VPN connection.
The following options are present in the list:
•
Quadro<>Peer – direct connection between Quadro and a
peer.
•
Quadro<>[Internet]<>Peer – connection between Quadro
and peer over Internet.
•
Quadro<>NAT<>[Internet]<>Peer – connection between
Quadro and peer over Internet through Quadro provider’s
NAT.
•
Quadro<>[Internet]<>NAT<>Peer – connection between
Quadro and peer over Internet through peer provider’s
NAT.
Fig. II-194: IPSec Connection Wizard - Add IPSec Connection
The second page of the IPSec Connection Wizard,
IPSec Connection Properties
serves to specify the members of the IPSec Connection and to
set the basic parameters for encryption.
A group of radio buttons are used with
Dynamic IP/Road Warrior
and
Static IP/ Remote Gateway
to select if the remote Quadro (or another VPN
gateway device) is connected to the Internet with a dynamic IP address and is acting as a
Road Warrior
, or is connected to the Internet with a fixed
IP address and is acting as a
VPN Gateway
.
If
Dynamic IP / RoadWarrior
is selected, the
Remote Gateway
IP Address
text field will automatically generate the value “any”, to allow access
independent from the sending IP address.
Selecting
Static IP / Remote Gateway
requires entering the
IP address or the hostname of the remote Quadro (or another
VPN gateway device) in the
Remote Gateway
text field.
Please Note:
The
Static IP/ Remote Gateway
selection is not
possible if this Gateway is positioned behind NAT, since the
IP-address of the remote gateway is not reachable directly in
this case.
Quadro <> Remote
Gateway
allows access from the local
Quadro to the remote VPN gateway (local subnet and remote
subnet are not included). This includes management access.
The
checkbox is disabled when
“Quadro<>NAT<>[Internet]<>Peer” or
“Quadro<>[Internet]<>NAT<>Peer” the is selected from the
VPN Network Topology
drop down list on the first page of the
IPSec Connection Wizard
.
Local Subnet <> Remote Gateway
allows access from all
stations connected to the local network to the remote VPN
gateway device (local Quadro and remote subnet are not
included). The checkbox is disabled when
“Quadro<>[Internet]<>NAT<>Peer” is selected from the
VPN
Network Topology
drop down list on the first page of the
IPSec Connection Wizard
.
Fig. II-195: IPSec Connection Wizard -IPSec Connection Properties
Quadro <> Remote Subnet
allows access from the local Quadro to all stations of the remote LAN (local subnet and remote VPN gateway devices
are not included). The checkbox is disabled when “Quadro<>NAT<>[Internet]<>Peer” is selected from the
VPN Network Topology
drop down list on
the first page of the
IPSec Connection Wizard
.
Local Subnet <> Remote Subnet
allows access from all stations of the local network to all stations of the remote LAN (VPN gateway devices are
not included). In this case, the local and remote subnet IP addresses and subnet masks have to be entered in the corresponding text fields
Local
Subnet IP
and
Remote Subnet IP
.
More than one of the above checkboxes may be selected to specify the desired communication relations.
The
Stop Connection if not successful
checkbox
allows you to stop the IPSec connection attempts if the partner is still unreachable after the
timeout period. If the checkbox is not selected, the system will continue to try to reach the IPSec connection partner.
The right side of the page offers the following security settings for key exchange, data encryption and authentication:
The area
Keying Type
offers the choice between automatic and manual keying. To use manual keying, the
Static IP / Remote Gateway
needs to
be selected.
Auto Keying
requires the
ESP
(Encapsulated Security payload) and
IKE
(Internet Key Exchange) settings (in addition to
Diffie-Helman Group
settings) to be selected for the automatic keying exchange.
Encryption
and
Authentication
parameters should be defined for each of these
standards, as well as for the
Manual Keying
.