A
CCESS
G
ATEWAY
System Administration
129
Next you will define selectors of the Security Policy. All selectors must match for the
policy to be applied.
4.
Define the following selectors for the
Remote End
:
Remote IP/Subnet
– Enter the IP address of the remote network secured by the IPSec
tunnel. The address can specify a host.
Subnet Mask
– Enter the subnet mask of the remote network secured by the IPSec
tunnel.
Remote UDP/TCP Port
– Enter the port number;
0
is for all ports (only if protocol is
UDP or TCP).
5.
Security Policy can derive the settings for the Local End from the current Network IP
settings of the unit. Select one of the following network options for the
Local End
:
Use current Network Interface IP Address
– Select this option if you would like to
use the current network interface IP Address. Note that the network IP address is
dynamic if DHCP or PPPoE client is enabled. This setting is the default setting.
Use this static IP address/subnet
– If you select this option you must also enter the
Local IP/Subnet
, the
Subnet Mask
, and the
IP address of network interface for
this policy
.
The
Local IP/Subnet
is the IP address of the local network secured by the
IPSec tunnel. The address can specify a host.
The
Subnet Mask
is the subnet mask of the local network secured by the IPSec
tunnel. The address can specify a host.
The
IP address of network interface for this policy
is the IP Address for the
NSE inside an IPSec tunnel. The IP address must be within the Local LAN
subnet or the same as the Local LAN IP address. IP address 0.0.0.0 disables the
functionality. The default setting is 0.0.0.0.
6.
Enter the port number in the
Local UDP/TCP Port
field;
0
is for all ports (only if protocol
is UDP or TCP).
7.
In the
Security Parameters
section, define the parameters of the security policy. The
options are
Discard
,
Bypass
,
ESP
, and
AH
.
ESP
is the default setting.
Discard
Bypass
– Select the direction of the discard/bypass; the options are:
In only
,
Out
only
, or
In and Out
.
Out only
is the default setting.
ESP
– Select all the acceptable encryption algorithms by putting a check in the
checkbox of each option; the options are:
DES
,
3DES
, and
NULL
.
3DES
is the default
setting. See
“
Setting joint ESP and AH parameters
” on page 130
to set
parameters that pertain to both ESP and AH polices.
Содержание Access Gateway
Страница 1: ......
Страница 12: ...ACCESS GATEWAY xii ...
Страница 51: ...ACCESS GATEWAY Introduction 39 ...
Страница 84: ...ACCESS GATEWAY 72 Installing the Access Gateway ...
Страница 90: ...ACCESS GATEWAY 78 Installing the Access Gateway ...
Страница 95: ...ACCESS GATEWAY System Administration 83 ...
Страница 96: ...ACCESS GATEWAY 84 System Administration ...
Страница 146: ...ACCESS GATEWAY 134 System Administration ...
Страница 161: ...ACCESS GATEWAY System Administration 149 ...
Страница 185: ...ACCESS GATEWAY System Administration 173 ...
Страница 205: ...ACCESS GATEWAY System Administration 193 The Network Interfaces screen appears ...
Страница 275: ...ACCESS GATEWAY System Administration 263 5 Repeat Steps 1 3 for page 3 of 3 see following screen ...
Страница 310: ...ACCESS GATEWAY 298 The Subscriber Interface ...
Страница 376: ...This page intentionally left blank ACCESS GATEWAY 364 Troubleshooting ...
Страница 378: ...This page intentionally left blank ACCESS GATEWAY 366 ...