14.1.2.11.3 Connection with XAuth Client
290
which has to be kept secret and a corresponding public key which does not have to
be protected.
In contrast authentication by preshared key can be compared to a simple password
authentication. Both peers have to know this key which of course has to remain secret.
This method is however a bad choice for client connections, as every connection which
involves dynamic IPs has to use the same preshared key.
specified X.509 certificates only
Using this option, the public key of the client must be imported on SX-GATE.
Drawback of this method: Whenever the peer changes its certificate (e.g. after
expiration) the new public key has to be imported before the VPN connection can
be reestablished. The administration effort will increase with the number of peers.
A certificate is only valid for a certain period of time (e.g.
1 year).
If you still want to use this option, please create a similar connection for each
client and import the corresponding certificate.
any certificate signed by trusted CA
This is the commonly used and recommended way for certificate based
authentication. The client is accepted if it presents a certificate which has been
issued by a Certificate Authority (CA) which is trusted by SX-GATE. The trusted
CA is configured at "Modules > Network > Settings".
SX-GATE's VPN server certificate must have been issued
by the same CA or otherwise authentication will fail.
As the client's certificate is not installed on SX-GATE it can be renewed anytime
without local changes. The only requirement is that the new certificate also has
to be issued by the trusted CA.
If the CA certificate expires, all certificates will become
invalid. However a CA certificate is usually valid for a longer
period of time (e.g. 10 years).
Preshared key
Using this setting, the peer will be authenticated by a preshared key.
Содержание SX-GATE
Страница 1: ...State 2016 12 13 V7 0 2 0 User Guide ...
Страница 92: ...12 1 Setup 92 There s no way to restore a purchased certificate without backup ...
Страница 126: ...12 3 3 Groups 126 12 3 3 C Usage This table show in which settings the definition is used ...
Страница 476: ...15 3 Apple iPhone 476 ...