14.1.2.11.4 Connection with L2TP Client
296
Remote ID (with CA based authentication)
Limit access to this connection to a single peer by entering the peer's ID. If you don't
know the peer's ID, you can find it in the logs after an attempt of the peer to establish
a VPN connection with SX-GATE. Certificate data (i.e. a Distinguished name, DN) is
expected as the peer's ID. It is not possible to enter an IP address or DNS name as
ID here.
This setting must be adjusted whenever the peer changes its
ID, e.g. because it received a new certificate and the new
certificate's DN differs from the old one.
Import public key
Here you can specify the public key of the client. If the client's certificate was issued
by the local SX-GATE CA, you can copy it from there. Otherwise you have to import
it from a file in PEM format.
You have to import the public key of the client itself and not the
public key of the issuing Certification Authority (CA).
14.1.2.11.4-B
Phase 1
The IKE proposals configured for peers with dynamic IP will always apply.
14.1.2.11.4-C
Phase 2
Dead Peer Detection
With Dead Peer Detection (DPD) enabled, SX-GATE checks every 30 seconds whether
the peer is still alive. The check is only performed when the link is idle. If there's no
reply for 120 seconds, the connection is terminated. In case of a peer with static IP
address, SX-GATE tries to negotiate a new connection.
The peer needs to support DPD according to RFC3706 if you
want to use this feature.
Содержание SX-GATE
Страница 1: ...State 2016 12 13 V7 0 2 0 User Guide ...
Страница 92: ...12 1 Setup 92 There s no way to restore a purchased certificate without backup ...
Страница 126: ...12 3 3 Groups 126 12 3 3 C Usage This table show in which settings the definition is used ...
Страница 476: ...15 3 Apple iPhone 476 ...