14.1.2.11.4 Connection with L2TP Client
294
14.1.2.11.4
Connection with L2TP Client
The configuration options in this menu are structured by topic. You can change between
the different screens by clicking on the tabs at the top.
14.1.2.11.4-A Authentication.......................................................... 294
14.1.2.11.4-B Phase 1................................................................... 296
14.1.2.11.4-C Phase 2................................................................... 296
14.1.2.11.4-D Connection.............................................................. 297
14.1.2.11.4-E Commands.............................................................. 298
14.1.2.11.4-A
Authentication
Authentication method
Please choose the authentication method used by the peer's. You can use either a
X.509 certificate based authentication or use a preshared key.
The efforts for configuring authentication with certificates are higher, however this
public key based method is conceptually more secure. Each peer has a private key
which has to be kept secret and a corresponding public key which does not have to
be protected.
In contrast authentication by preshared key can be compared to a simple password
authentication. Both peers have to know this key which of course has to remain secret.
This method is however a bad choice for client connections, as every connection which
involves dynamic IPs has to use the same preshared key.
specified X.509 certificates only
Using this option, the public key of the client must be imported on SX-GATE.
Drawback of this method: Whenever the peer changes its certificate (e.g. after
expiration) the new public key has to be imported before the VPN connection can
be reestablished. The administration effort will increase with the number of peers.
A certificate is only valid for a certain period of time (e.g.
1 year).
If you still want to use this option, please create a similar connection for each
client and import the corresponding certificate.
Содержание SX-GATE
Страница 1: ...State 2016 12 13 V7 0 2 0 User Guide ...
Страница 92: ...12 1 Setup 92 There s no way to restore a purchased certificate without backup ...
Страница 126: ...12 3 3 Groups 126 12 3 3 C Usage This table show in which settings the definition is used ...
Страница 476: ...15 3 Apple iPhone 476 ...