Nortel 3050 Command Reference Manual page 147

Vpn gateway
Hide thumbs Also See for 3050:
Table of Contents

Advertisement

/cfg/ssl/server <number> /adv /sslconnect SSL Connect Configuration 147
Table 42
SSL Connect Settings Menu Options (/cfg/ssl/server/adv/sslconnect) (cont'd.)
Command Syntax and Usage
ciphers <cipher list format>
verify
ena
Copyright © 2007 Nortel Networks
.
Specifies which client certificate the selected virtual SSL server should
present to the backend servers, in case the SSL software on the backend
servers is configured to require a client certificate. Client authentication is
typically very seldom used for SSL connections between the VPN Gateways
and the backend servers, as the client is known in these circumstances.
To view basic information about available certificates, use the
/info/certs command. To generate a client certificate, see the
"Generating Client Certificates" section in the "Certificates and Client
Authentication" chapter in the User's Guide.
Specifies the list of preferred ciphers. This information is sent to the
backend servers during the SSL handshake. The default cipher list
corresponds to EXP-RC4-MD5:ALL!DH, which should be appropriate in
most cases. The default cipher list provides for using lighter encryption
algorithms between the VPN Gateways and the backend servers than
what is normally used between Internet clients and the VPN Gateways.
This is desirable mainly in terms of SSL performance. Since both the
VPN Gateways and the backend servers typically are behind a firewall in
physically secured premises, using lighter encryption algorithms on this
network segment should not compromise the overall security.
If you change the default list of preferred ciphers, make sure the specified
ciphers are included in the backend servers' list of preferred ciphers as the
SSL connection will otherwise be refused.
For more information about supported ciphers and cipher list formats, see
Appendix A, Supported Ciphers, in the User's Guide.
Displays the SSL Connect Verify Settings menu. To view menu options, see
"/cfg/ssl/server <id> /adv /sslconnect/verify SSL Connect
Verify Configuration" (page
Enables SSL connections between the selected virtual SSL server and
configured backend servers. By default, SSL connect is disabled.
For greater control, you can disallow SSL connections to a particular
backend server by using the sslconnect command in the Backend
Server menu. For more information, see the sslconnect command on
"sslconnect on|off" (page 144)
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
148).
.

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

3070Nvg 3050Nvg 3070Svm 10001000 con?guration guide

Table of Contents