14.1.2.11.1 Connection with Server
278
14.1.2.11.1-B
Authentication
Authentication method
Please choose the authentication method used by the peer's. You can use either a
X.509 certificate based authentication or use a preshared key.
The efforts for configuring authentication with certificates are higher, however this
public key based method is conceptually more secure. Each peer has a private key
which has to be kept secret and a corresponding public key which does not have to
be protected.
In contrast authentication by preshared key can be compared to a simple password
authentication. Both peers have to know this key which of course has to remain secret.
However in contrast to a password the key should be longer and more complicated.
specified certificate
Using this option, the public key of the peer must be imported on SX-GATE.
Drawback of this method: Whenever the peer changes its certificate (e.g. after
expiration) the new public key has to be imported before the VPN connection can
be reestablished. The administration effort will increase with the number of peers.
A certificate is only valid for a certain period of time (e.g.
1 year).
Certificate by CA
This is the commonly used and recommended way for certificate based
authentication. The peer is accepted if it presents a certificate which has been
issued by a Certificate Authority (CA) which is trusted by SX-GATE. The trusted
CA is configured at "Modules > Network > Settings".
SX-GATE's VPN server certificate must have been issued
by the same CA or otherwise authentication will fail.
As the certificate of the peer itself is not installed on SX-GATE it can be renewed
by the peer anytime without local changes. The only requirement is that the new
certificate also has to be issued by the trusted CA.
If the CA certificate expires, all certificates will become
invalid. However a CA certificate is usually valid for a longer
period of time (e.g. 10 years).
Содержание SX-GATE
Страница 1: ...State 2016 12 13 V7 0 2 0 User Guide ...
Страница 92: ...12 1 Setup 92 There s no way to restore a purchased certificate without backup ...
Страница 126: ...12 3 3 Groups 126 12 3 3 C Usage This table show in which settings the definition is used ...
Страница 476: ...15 3 Apple iPhone 476 ...