Nortel 3050 Command Reference Manual page 291

Vpn gateway
Hide thumbs Also See for 3050:
Table of Contents

Advertisement

/cfg/vpn <id> /server/adv/sslconnect /verify SSL Connect Verify Configuration 291
Table 103
SSL Connect Settings Menu Options (/cfg/vpn/server/adv/sslconnect) (cont'd.)
Command Syntax and Usage
ciphers <cipher list format>
verify
/cfg/vpn <id> /server/adv/sslconnect /verify SSL Connect
Verify Configuration
[SSL Connect Verify Settings Menu]
verify
common name
cacerts
The SSL Connect Verify Settings menu is used for configuring the desired
certificate verification level when back end servers are authenticated. The
menu is also used to specify the common name of backend servers, as
well as setting the CA certificates used for backend server authentication.
Copyright © 2007 Nortel Networks
.
Specifies the list of preferred ciphers. This information is sent to the
backend servers during the SSL handshake. The default cipher list
corresponds to EXP-RC4-MD5:ALL!DH, which should be appropriate in
most cases. The default cipher list provides for using lighter encryption
algorithms between the VPN Gateways and the backend servers than
what is normally used between Internet clients and the VPN Gateways.
This is desirable mainly in terms of SSL performance. Since both the
VPN Gateways and the backend servers typically are behind a firewall
in physically secured premises, using lighter encryption algorithms on
this network segment should not compromise the overall security.
If you change the default list of preferred ciphers, make sure the
specified ciphers are included in the backend servers' list of preferred
ciphers as the SSL connection will otherwise be refused.
For more information about supported ciphers and cipher list formats,
see Appendix A, Supported Ciphers, in the User's Guide.
Displays the SSL Connect Verify Settings menu. To view menu options,
see
"/cfg/ssl/server <id> /adv /sslconnect/verify SSL
Connect Verify Configuration" (page
- Set certificate verification level
- Set server common name
- Set list of accepted signers of server's certificate
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
148).

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

3070Nvg 3050Nvg 3070Svm 10001000 con?guration guide

Table of Contents