Configuring Xauth For Vpn Clients - NETGEAR ProSafe DGFV338 Reference Manual

Prosafe wireless adsl modem vpn firewall router
Hide thumbs Also See for ProSafe DGFV338:
Table of Contents

Advertisement

DGFV338 ProSafe Wireless ADSL Modem VPN Firewall Router Reference Manual
IPSec Host. If you want authentication by the remote gateway, enter a User Name and
Password to be associated with this IKE policy. If this option is chosen, the remote gateway
must specify the user name and password used for authenticating this gateway.
Note: If a RADIUS-PAP server is enabled for authentication, XAUTH will first check the
local User Database for the user credentials. If the user account is not present, the
router will then connect to a RADIUS server.

Configuring XAUTH for VPN Clients

Once the XAUTH has been enabled, you must establish user accounts on the Local Database to be
authenticated against XAUTH, or you must enable a RADIUS-CHAP or RADIUS-PAP server.
Note: If you are modifying an existing IKE Policy to add XAUTH, if it is in use by a
VPN Policy, the VPN policy must be disabled before you can modify the IKE
Policy.
To enable and configure XAUTH:
1. Select VPN from the main menu and Policies from the submenu. The IKE Policies screen will
display.
2. You can add XAUTH to an existing IKE Policy by clicking Edit adjacent to the policy to be
modified or you can create a new IKE Policy incorporating XAUTH by clicking Add.
3. In the Extended Authentication section check the Edge Device radio box to use this router as
a VPN concentrator where one or more gateway tunnels terminate. You then must specify the
authentication type to be used in verifying credentials of the remote VPN gateways. (Either the
User Database or RADIUS Client must be configured when XAUTH is enabled.)
4. In the Extended Authentication section, select the Authentication Type from the pull-down
menu which will be used to verify user account information. Select
Edge Device to use this router as a VPN concentrator where one or more gateway tunnels
terminate. When this option is chosen, you will need to specify the authentication type to
be used in verifying credentials of the remote VPN gateways.
User Database to verify against the router's user database. Users must be added
through the User Database screen (see
Virtual Private Networking
"User Database Configuration" on page
v1.0, April 2007
5-29).
5-27

Advertisement

Table of Contents
loading

Table of Contents