13.1.4 XAUTH Profiles
In the XAUTH Profiles menu a list of all XAUTH profiles is displayed.
Extended Authentication for IPSec (XAuth) is an additional authentication method for
IPSec tunnel users.
The gateway can take on two different roles when using XAuth as it can act as a server or
as a client:
• As a server the gateway requires a proof of authorisation.
• As a client the gateway provides proof of authorisation.
In server mode multiple users can obtain authentication via XAuth, e.g. users of Apple
iPhones. Authorisation is verified either on the basis of a list or via a Radius Server. If us-
ing a one time password (OTP), the password check can be carried out by a token server
(e.g. SecOVID from Kobil), which is installed behind the Radius Server. If a company's
headquarters is connected to several branches via IPSec, several peers can be con-
figured. A specific user can then use the IPSec tunnel over various peers depending on
the assignment of various profiles. This is useful, for example, if an employee works al-
ternately in different branches, if each peer represents a branch and if the employee
wishes to have on-site access to the tunnel.
XAuth is carried out once IPSec IKE (Phase 1) has been completed successfully and be-
fore IKE (Phase 2) begins.
If XAuth is used together with IKE Config Mode, the transactions for XAuth are carried out
before the transactions for IKE Config Mode.
13.1.4.1 New
Choose the New button to create additional profiles.
The VPN->IPSec->XAUTH Profiles ->New menu consists of the following fields:
Fields in the Basic Parameters menu
Field
Description
Description
Enter a description for this XAuth profile.
Role
Select the role of the gateway for XAuth authentication.
Possible values:
Gigaset Communications GmbH
13 VPN
hybird 120 Gigaset Edition
277