![insys icom EBW-E100 Скачать руководство пользователя страница 55](http://html1.mh-extra.com/html/insys-icom/ebw-e100/ebw-e100_manual_2070385055.webp)
EBW-E100
Functions
55
In order to configure the authentication with certificates, select the radio
button "Authentication based on certificate". It is indicated under the
option here, whether the individual certificates and keys are present
(green checkmark) or not (red cross). Present certificates can also be
downloaded (blue arrow) or deleted again (red cross on white box). The
private key can only be deleted. Check the checkbox " Activate tls-auth"
to use a static key as well in addition to the certificates. The static key
stored in the "Authentication with preshared key" section will then be
used. Optionally, a direction can be specified in the "Use direction of
key" drop-down list (refer to the note in the following for this). Check the
checkbox "Allow communication between clients" to enable a
communication between the clients as well. Define the IP address pool
for the clients in the fields "IPv4 address pool / Netmask" or "IPv6
address pool / Netmask". In order to create a new route to a client
network, enter in the section "Create new route to a client network" the
Common Name of the client into the field "Name in certificate" as well as
its net address and netmask into the fields "IPv4 net address / netmask"
or "IPv6 net address / netmask". Optionally, enter the VPN IPv4 address
for the tunnel end of a client into the field "VPN IPv4 address". One IPv4
and one IPv6 address will always be assigned to each tunnel end, even if
the tunnel of one IP version is not used at all. Click on "OK" to take over
the new route. You can delete existing routes by checking the checkbox
in the column "delete" of the respective route and clicking on "OK".
If tls-auth is used, it is possible to specify that the static key can only
be used for a certain direction. It is important here that this setting is
harmonised with the remote VPN terminal, i.e. no direction is
configured for bot or the settings are complementary (0/1 or 1/0).
A link of a network address with "DEFAULT" as "Common Name" may
be created as "Standard route". It is always used as route, when a
client registers with a certificate, for whose "Common Name" no other
link has been entered.