Bridge GUI Guide: Security Configuration
132
To delete IPsec peer PSKs:
1
Log on to the Bridge GUI through an
Administrator
-level
account and select
Configure
->
IPsec
from the menu on the
left.
2
In the
IPsec Settings
screen’s
Pre-Shared Keys
frame:
If you want to delete the PSK for a single or selected
IPsec peers, click to place a checkmark in the box(es)
beside the IP address(es) of the peer(s) for which you
want to delete the PSK(s).
or
If you want to delete all IPsec peer PSKs, click
ALL
at
the top of the
Pre-Shared Keys
list to check all IP
addresses.
Click the
Pre-Shared Keys
frame’s
DELETE
PSK
button.
The IP addresses of the IPsec peers whose PSKs are deleted
are removed from the
Pre-Shared Keys
list.
4.2.4
IPsec Access Control List
An additional level of security can be provided in the Bridge’s
IPsec implementation via the IPsec ACL.
The function is enabled when at least one ACL entry is
configured. It is disabled by default: no ACL entries are
present.
When the IPsec access control function is enabled, the Bridge
compares the Distinguished Names (DNs) contained in the
X.509 digital certificates of authenticating IPsec peers against
those recorded in the IPsec ACL. If no match is found, access
is denied. If a match is found, access is allowed or denied
according to the ACL entry’s
Access
rule.
Figure 4.7.
IPsec ACL
entry frame, all platforms
You can configure up to 100 IPsec ACL entries to be applied in
the specified priority. Settings include:
Name
- identifies the ACL entry in the Bridge configuration.
Distinguished Name
- specifies the DN pattern against
which those in the X.509 certificates of IPsec peers will be
matched. Each RDN (Relative Distinguished Name) in the
sequence comprising the certificate DN is compared to the
corresponding RDN specified in the IPsec ACL entry. You
can use wildcard characters (
*
) in the RDNs that comprise
the
Distinguished Name
specified for an ACL entry.
For example, the DN pattern:
C=US, ST=Florida, O=*