background image

Doc.Ref 

TgbVpn25x_en 

Doc.version 

1.2 – Nov.2004 

 

VPN version 

2.50 

 

IPSec VPN Client User Manual 

Property of Sistech SA - © Sistech 2004 

12/12 

 

4.4.1

 

Settings description 

 

Name 

Label for Authentication phase used only the configuration user interface. This 

value is never used during IKE negotiation. It is possible to change this name 
at any time and read it in the tree control. Two Phase 1 can not have the same 

name. 

Interface 

IP address of the network interface of the computer, through which VPN 
connection is established. If the IP address may change (when it is received 

dynamically by an ISP), select "*". 

Remote Gateway 

IP address or DNS address of the remote gateway (in our example: 

gateway.mydomain.com). 

This field is mandatory

Pre-shared key 

Password or key shared with the remote gateway. 

Certificate 

X509 certificate used by the VPN client (see certificate configuration). 

IKE encryption 

Encryption algorithm used during Authentication phase (3DES, AES, ...). 

IKE authentication 

Authentication algorithm used during Authentication phase (MD5, SHA, ...). 

IKE key group 

Diffie-Hellman key length. 

 

Once the parameters are set, click on “Save & Apply” to save and to take into account the new configuration. 
 

4.4.2

 

Advanced configuration ("Advanced" Button) 

 

 

 

4.4.3

 

Settings description 

 

Aggressive Mode  

If checked, the VPN client will used aggressive mode as negociation mode with 
the remote gateway 

Nat port 

Negociation port for IKE. Default value is 500. 

Local ID 

Local ID is the identity the VPN client is sending during Phase 1 to VPN 
gateway. 

This identity can be: 

?

 

an IP address (type = IP address), for example: 195.100.205.101 

?

 

an domaine name (type = DNS), e.g. mydomain.com  

?

 

an email address (type = Email), e.g. 

[email protected]

 

Содержание THEGREENBOW VPN-CLIENT -

Страница 1: ...x_en Doc version 1 2 Nov 2004 VPN version 2 50 IPSec VPN Client User Manual Property of Sistech SA Sistech 2004 1 1 TheGreenBow VPN Client User Manual WebSite http www thegreenbow com Contact support...

Страница 2: ...1 How to create a tunnel 10 4 3 2 Several Authentication or IPSec Configuration Phases 11 4 3 3 Active or Non Active phase 11 4 4 Authentication or Phase 1 11 4 4 1 Settings description 12 4 4 2 Adva...

Страница 3: ...ated areas Our IKE implementation is based on the OpenBSD 3 1 implementation ISAKMPD thus providing best compatibility with existing IPSec routers and gateways Our offer is specially designed to targe...

Страница 4: ...taskbar from menu Start Programs TheGreenBow VPN TheGreenBow VPN 2 2 Evaluation Period It is possible to use TheGreenBow IPSec VPN Client during the evaluation period i e limited to 30 days by clickin...

Страница 5: ...en all the VPN tunnels Console shows log window Connections opens the list of already established VPN tunnels You can configure tunnels to open up automatically when the software starts 3 2 Hidden Use...

Страница 6: ...window About 3 3 2 Status bar The status bar displays several information The USB Token box left side indicates whether the USB mode is set On or Off see also section 4 1 page 7 In case it is set On...

Страница 7: ...he capability to secure tunnel security elements by the use of a USB Stick Once the USB mode is set On you just need to insert the USB stick to automatically open tunnels And you just need to unplug t...

Страница 8: ...ck When you insert a new USB stick the IPSec VPN Client automatically propose to enable the USB stick through the following options Copying the configuration onto the USB stick the VPN client will cop...

Страница 9: ...a VPN gateway Let take the following example The remote computer has a dynamically provided public IP address It tries to connect the Corporate LAN behind a VPN gateway that has a DNS address gateway...

Страница 10: ...gured directly via the main interface e g Certificates virtual IP address etc 4 3 Tunnel configuration main window 4 3 1 How to create a tunnel To create a VPN tunnel from the main window without usin...

Страница 11: ...for a same Authentication Phase Phase 1 4 3 3 Active or Non Active phase A phase can be either active or non active If a phase is non active its settings will not be applied This feature can be used...

Страница 12: ...rd or key shared with the remote gateway Certificate X509 certificate used by the VPN client see certificate configuration IKE encryption Encryption algorithm used during Authentication phase 3DES AES...

Страница 13: ...address type IP address for example 80 2 3 4 an domaine name type DNS e g gateway mydomain com an email address type Email e g admin mydomain com a string type KEY ID e g 123456 a certificate issuer...

Страница 14: ...bnet address ESP encryption Encryption algorithm negociated during IPSec phase 3DES AES ESP authentication Authentication algorithm negociated during IPSec phase MD5 SHA ESP mode IPSec encapsulation m...

Страница 15: ...configuring IPSec VPN Client with certificates 1 Select radio button Certificate in the Authentication window and click on Certificates Mgt 2 Click on Browse and select the appropriate files Root cert...

Страница 16: ...ying IPSec minimal lifetime Default lifetime for IPSec rekeying IPSec maximal lifetime Maximal lifetime for IPSec rekeying IPSec minimal lifetime Minimal lifetime for IPSec rekeying Retransmissions Ho...

Страница 17: ...guration files will have a tgb extension You can open and modify an exported configuration file extension tgb with any word processing e g Notepad and re import it again This is other way for IT manag...

Страница 18: ...es During PC boot this mode can be used for secure remote action At Windows login login mode Launched by user or from a script manual mode The latest version of this tool is available on our website w...

Страница 19: ...r log level about timers Sdep Sysdep log level about IKE interface from to IPSec SA SA log level for SA managment Exch Exchange log level about IKE exchanges very useful Nego Negotiation log level abo...

Страница 20: ...IPSec VPN Client User Manual Property of Sistech SA Sistech 2004 20 20 8 Support Information and update are available at http www thegreenbow com Technical support by email at support thegreenbow com...

Отзывы: