SonicWALL VPN Page 149
Configuring a VPN Security Association using IKE and a Third Party Certificate
To create a VPN SA using IKE and third party certificates, follow these steps:
1. Click
VPN
, then
Configure
. In the
Add/Modify IPSec Associations
section, Select
IKE
using 3rd Party Certificates
from the
IPSec Keying
Mode
menu.
2. Enter a Name for the Security Association in the
Name
field.
3. Select a certificate from the
Select Certificate
list.
4. Enter the Gateway address in the
IPSec Gateway Address
field.
5. In the
Security Policy
section, select the type of DH group from the
Phase 1 DH Group
menu.
6. The
SA Lifetime (secs)
automatically defaults to 28800 seconds (8 hours).
7. Select the type of
Phase 1 Encryption/Authentication
from the menu.
8. Select the type of
Phase 2 Encryption/Authentication
from the menu.
9. In the
Peer Certificate’s ID
section, you must select the ID Type from the
ID Type
menu. You can select
Distinguished
Name
,
E-mail ID
, or
Domain
Name
from the
menu. Then cut and paste the information from the Local Certificate into the text field.
10. In the
Destination
Networks
section, select the type of destination for the VPN tunnel.
Use this SA as default route for all Internet traffic
can be used for only one SA, and
routes all VPN traffic destined for the WAN through the SA. If you are allowing computers
at the VPN destination to obtain an IP address dynamically through the VPN tunnel, select
Destination
network obtains IP addresses using DHCP through this SA
. If the VPN
destination is a specific IP address, select
Specify destination network below
and click
Add New Network...
Enter the network IP address and subnet mask in the fields, and
click
OK
.
Advanced Settings
•
Use Aggressive Mode
•
Enable Keep Alive
•
Require authentication of local users
•
Require authentication of remote users
-
Remote users behind VPN gateway
-
Remote VPN clients with XAUTH
•
Enable Windows Networking (NetBIOS) broadcast
•
Apply NAT and firewall rules
•
Forward packets to remote VPNs
•
Enable Perfect Forward Secrecy
Содержание TELE3 SP
Страница 1: ...SONICWALL The TELE3 SP Administrator s Guide...
Страница 204: ...Appendices Page 203 Notes...
Страница 205: ...Page 204 SonicWALL TELE3 SP Administrator s Guide...