
FireBrick FB6402 User Manual
vii
11.1.1.4. IKE ................................................................................................... 66
11.1.1.5. Manual Keying ................................................................................... 66
11.1.1.6. Identities and the Authentication Mechanism ............................................ 67
11.1.2. Setting up IPsec connections ........................................................................... 67
11.1.2.1. Global IPsec parameters ....................................................................... 67
11.1.2.2. IKE proposals ..................................................................................... 68
11.1.2.3. IKE roaming IP pools .......................................................................... 68
11.1.2.4. IKE connections .................................................................................. 68
11.1.2.4.1. IKE connection mode and type ................................................... 68
11.1.2.4.2. IKE and IPsec proposal lists ....................................................... 68
11.1.2.4.3. Authentication and IKE identities ................................................ 69
11.1.2.4.4. IP addresses ............................................................................. 69
11.1.2.4.5. Road Warrior connections .......................................................... 70
11.1.2.4.6. Routing ................................................................................... 70
11.1.2.4.7. Other parameters ...................................................................... 70
11.1.2.5. Setting up Manual Keying .................................................................... 70
11.1.2.5.1. IP endpoints ............................................................................. 71
11.1.2.5.2. Algorithms and keys ................................................................. 71
11.1.2.5.3. Routing ................................................................................... 71
11.1.2.5.4. Mode ...................................................................................... 71
11.1.2.5.5. Other parameters ...................................................................... 72
11.1.3. Using EAP with IPsec/IKE ............................................................................. 72
11.1.4. Using certificates with IPsec/IKE ..................................................................... 72
11.1.4.1. Creating certificates ............................................................................. 74
11.1.5. Choice of algorithms ...................................................................................... 74
11.1.6. NAT Traversal .............................................................................................. 75
11.1.7. Configuring a Road Warrior server ................................................................... 76
11.1.8. Connecting to non-FireBrick devices ................................................................. 77
11.1.8.1. Using StrongSwan on Linux ................................................................. 77
11.1.8.2. Setting up a Road Warrior VPN on an Android client ................................ 78
11.1.8.3. Setting up a Road Warrior VPN on an iOS (iPhone/iPad) client .................... 79
11.1.8.4. Manual keying using Linux ipsec-tools ................................................... 79
11.2. FB105 tunnels ......................................................................................................... 80
11.2.1. Tunnel wrapper packets .................................................................................. 81
11.2.2. Setting up a tunnel ......................................................................................... 81
11.2.3. Viewing tunnel status ..................................................................................... 82
11.2.4. Dynamic routes ............................................................................................. 82
11.2.5. Tunnel bonding ............................................................................................. 82
11.2.6. Tunnels and NAT .......................................................................................... 82
11.2.6.1. FB6000 doing NAT ............................................................................. 83
11.2.6.2. Another device doing NAT ................................................................... 83
11.3. Ether tunnelling ....................................................................................................... 83
12. System Services ................................................................................................................. 85
12.1. Protecting the FB6000 .............................................................................................. 85
12.2. Common settings ..................................................................................................... 85
12.3. HTTP Server configuration ........................................................................................ 86
12.3.1. Access control ............................................................................................... 86
12.3.1.1. Trusted addresses ................................................................................ 86
12.4. Telnet Server configuration ........................................................................................ 86
12.4.1. Access control ............................................................................................... 87
12.5. DNS configuration ................................................................................................... 87
12.5.1. Blocking DNS names ..................................................................................... 87
12.5.2. Local DNS responses ..................................................................................... 87
12.5.3. Auto DHCP DNS .......................................................................................... 87
12.6. NTP configuration .................................................................................................... 88
12.7. SNMP configuration ................................................................................................. 88
Содержание FB6402
Страница 1: ...FireBrick FB6402 User Manual FB6000 Versatile Network Appliance...
Страница 2: ......