14.1.2.11.2 Connection with Client
286
If the CA certificate expires, all certificates will become
invalid. However a CA certificate is usually valid for a longer
period of time (e.g. 10 years).
Preshared key
Using this setting, the peer will be authenticated by a preshared key.
All connections with dynamic IPs involved must use the
same key. Therefore it is configured along with the settings
of the ipsec interface and not with the connection specific
settings.
Remote ID (with PSK)
With preshared key authentication the peers identify each other using an IP address,
a hostname (FQDN) or an email address (USER@FQDN). To restrict this connection
to a client with a certain ID you can enter its ID here. If you don't know the peer's ID,
you can find it in the logs after an attempt of the peer to establish a VPN connection
with SX-GATE.
A client with dynamic IP which identifies itself by its IP must
provide an option to set a static ID. Otherwise it is not identifiable
by ID.
Remote ID (with CA based authentication)
Limit access to this connection to a single peer by entering the peer's ID. If you don't
know the peer's ID, you can find it in the logs after an attempt of the peer to establish
a VPN connection with SX-GATE. Certificate data (i.e. a Distinguished name, DN) is
expected as the peer's ID. It is not possible to enter an IP address or DNS name as
ID here.
This setting must be adjusted whenever the peer changes its
ID, e.g. because it received a new certificate and the new
certificate's DN differs from the old one.
Import public key
Here you can specify the public key of the client. If the client's certificate was issued
by the local SX-GATE CA, you can copy it from there. Otherwise you have to import
it from a file in PEM format.
Содержание SX-GATE
Страница 1: ...State 2016 12 13 V7 0 2 0 User Guide ...
Страница 92: ...12 1 Setup 92 There s no way to restore a purchased certificate without backup ...
Страница 126: ...12 3 3 Groups 126 12 3 3 C Usage This table show in which settings the definition is used ...
Страница 476: ...15 3 Apple iPhone 476 ...