Page 3
SSH Communications Security Corp. All products or technologies are the trademarks or registered trademarks of their respective holders. Multi-Tech Systems, Inc. 2205 Woodale Drive Mounds View, Minnesota 55112 (763) 785-3500 or (800) 328-9717 Fax 763-785-9874 Tech Support (800) 972-2439 Internet Address: http://www.multitech.com...
RFIPSC Quick Start Guide Chapter 1 – Introduction and Description Introduction Welcome to Multi-Tech’s new RouteFinder, model RF650VPN. The RF650VPN is an Internet security appliance that lets you use data encryption and the Internet to securely connect to telecommuters, remote offices, customers or suppliers while avoiding the cost of expensive private leased lines.
PN 82013151 Internet Protocol (IP) The open architecture of the Internet Protocol (IP) makes it a highly efficient, cost- effective and flexible communications protocol for local and global communications. IP is widely adopted, not only on the global Internet, but also in the internal networks of large corporations.
RFIPSC Quick Start Guide About this Manual and Related Manuals This Quick Start Guide manual contains four chapters and one appendix, and is intended to provide the experienced client user or system administrator with the information needed to quickly get the SSH IPSec Client software up and running. The full Sentinel SSH IPSec Client User Guide manual is provided on the SSH IPSec Client CD-ROM included in the license pak.
RFIPSC Quick Start Guide Chapter 2 - SSH IPSec Client Installation and Setup Introduction This section describes the SSH Sentinel software, an IPSsec client product by SSH Communications Security Corp, providing secure communications over a TCP/IP connection. The Sentinel SSH software is used by client devices for secure connection to the Multi-Tech RouteFinder model RF650VPN.
PN 82013151 To run the SSH Sentinel client software, you need a personal computer with at least the following configuration: Processor Pentium 100 MHz Memory (RAM) 32 MB for Windows 9x, or 64 MB for Windows NT4/2000 Hard disk space 10 megabytes of free disk space Network connection TCP/IP network protocol Starting the SSH Sentinel Installation The SSH Sentinel installation requires that you have full access rights for the system...
Page 13
RFIPSC Quick Start Guide The installer will run Installation Wizard, which creates the initial configuration and sets up the SSH Sentinel client software. Note: If a previous version of the SSH Sentinel software is installed on your computer and you try to install a new version, the wizard updates the software and the steps described here are skipped.
PN 82013151 Figure 4. Choose Destination Path. Authentication Key Generation The SSH Sentinel Installation Wizard generates a primary authentication key for IPSec peer (host) authentication purposes. The primary authentication key is a 1024-bit RSA key pair that is used for digital signatures and strong authentication. Authentication key generation begins with random seed generation.
PN 82013151 Identity Information 5. SSH Sentinel uses certificates and digital signatures as its primary authentication method. SSH Sentinel processes certificates according to the IETF Public-Key Infrastructure X.509v3 standards, allowing you to take advantage of the public-key infrastructure (PKI). SSH Sentinel supports certificate revocation lists (CRLs) and authority revocation lists (ARLs, that is, CRLs for CAs) and is very configurable.
RFIPSC Quick Start Guide Choose the Enrollment Method 6. A certification request can be created as part of the installation process. You can either enroll online, in other words create and send the request immediately, or save the request in a file and deliver it later to the certification authority (CA). If there is no certification authority available or you for some reason want to postpone the creation of the request, create a self-signed certificate.
Page 18
PN 82013151 Online Enrollment Information To enroll online, you must locate the certification authority server and you must possess the certification authority certificate. Most often, you can download the certificate of the certification authority from its web site. Figure 9. Online Enrollment Settings You must also specify the enrollment protocol.
Page 19
RFIPSC Quick Start Guide either saved it in a file or copied the contents of it to the Windows clipboard. In a file, the certificate may be in binary (X.509), PEM (Privacy Enhanced Mail) or HEX format. Pasted from the clipboard, the certificate must be in PEM encoded format. Advanced button (D) Opens a dialog box for configuring the socks and proxy settings.
PN 82013151 you may prefer sending the request via email or using an enrollment service on the Web. Select PKCS#10 request file location In the text field (callout A in Figure 10 above), enter the path and the name of the file where the certification request will be stored.
RFIPSC Quick Start Guide encryption hardware vendors. It has the advantage of giving simple figures on the speed: Due to a number of variables that affect the final result, it would be very complicated to define a standard environment in which to reliably measure the overall network throughput.
PN 82013151 SSH IPSec Client Setup The RouteFinder supports VPN (Virtual Private Networking), which provides the ability to encrypt IP network traffic. Host 1 <----> Router <----> Internet <----> Router <----> Host 2 <----------------- encrypted -------------------> All communication between the hosts uses strong encryption, so that nobody is able to listen to this communication.
PN 82013151 Sentinel Configuration 4. From the Control panel select the Sentinel Policy Editor 5. At select Key Management Authentication Keys 6. Click...
Page 25
RFIPSC Quick Start Guide 7. Click to create a new Authentication Key. 8. Check the and click Create new preshared key checkbox...
Page 26
PN 82013151 9. Select a Primary Identifier from the drop down list. Select Primary Identifier Select a and click Host IP Address 10. Enter the and click Preshared Key Information...
Page 28
PN 82013151 12. Select the information and click Note Security Gateway Intranet IP Address that the System routing is set automatically. The RouteFinder looks for Subnet Mask that you entered. Intra IP Address If the that you entered is not found, the Intra IP Address Probe Results unsuccessful...
Page 29
RFIPSC Quick Start Guide 13. Click screen is displayed. Details>> Connection Properties General 14. Edit the and the then change the IP Address Settings Proposal Parameters Rule (if necessary). Click Comment...
Page 30
PN 82013151 15. Click on the tab. Advanced 16. As necessary, edit the Advanced Options NAT Traversal Virtual IP Address Settings and/or check the check box and click Enable Extended Authentication The Probe Results screen displays.
Page 32
PN 82013151 18. Verify the connection details information and click Close...
Page 33
RFIPSC Quick Start Guide The Security Policy begins updating. 19. When the Security Policy is done updating, click to Ping the new Diagnostics ... connection.
Page 34
PN 82013151 If the ping is successful, the Host to NET using SSH Sentinel 1.1.1 (static IP) to connect to a RouteFinder using Pre Shared Keys (PSK) process is complete.
RFIPSC Quick Start Guide SSH Sentinel Installation Notes SSH Sentinel supports Microsoft Windows 95/98, Windows Me, Windows NT 4.0 and Windows 2000. The SSH Sentinel software download site is at http://www.ssh.com/products/sentinel/beta/. Start the SSH Sentinel setup program ( ) by double clicking the icon and Sentinel.exe follow instructions on the screen.
PN 82013151 Updating SSH Sentinel If you launch the installation package with a previous version of SSH Sentinel software on your computer, the existing version is automatically updated. The contents (i.e., the policies, the rules, the authentication keys, etc.) are preserved. Only the software version is updated.
On-line Warranty Registration If you would like to register your RouteFinder electronically, you can do so at the following address: http://www.multitech.com/register/ Tech Support. Multi-Tech has an excellent staff of technical support personnel available to help you get most out of your Multi-Tech product. If you have any questions about the operation of this unit, call 1-800-972-2439.
_______________________________________________________________ Contacting Tech Support via E-mail If you prefer to receive technical support via the Internet, you can contact Tech Support via e-mail at support@multitech.com or from http://www.multitech.com/ . When responding to e-mails from our technical staff please attach all previous e-mails to assist us in giving you a speedy response.
Multi-Tech’s presence includes a Web site at http://www.multitech.com and an ftp site at ftp://ftp.multitech.com. Ordering Accessories SupplyNet, Inc. supplies replacement transformers, cables and connectors for select Multi-Tech products. You can place an order with SupplyNet via mail, phone, fax or the Internet at: Mail: SupplyNet, Inc.
Page 40
PN 82013151 SupplyNet On-line Ordering Instructions 1. Browse to http://www.thesupplynet.com. In the drop-down Browse by Manufacturer list, select and click Multi-Tech 2. To order, type in the quantity, and click Add to Order 3. Click to change your order. Review Order 4.
RFIPSC Quick Start Guide Appendix A - RFIPSC-5/10/50 Client Software CD The RouteFinder RFIPSC-5/10/50 CD contains the SSH Sentinel IPSec Client files as shown below. When you insert the CD in your computer's CD-ROM drive, the SSH Sentinel IPSec Client software Install screen displays.
Page 42
PN 82013151 Click Install IPSEC Client Software to load the SSH Sentinel IPSec Client Software and either run the program from the CD or save it to your computer's hard disk drive (the initial screen is shown below). Click Read the End User Licensing Agreement to view the Multi-Tech Multi-User Software License Agreement (the initial screen is shown below).
Page 43
(this document). You can also find it directly on the CD in Acrobat format (InstallationGuide.pdf), as well as on the Multi-Tech web site (http://www.multitech.com). This is an Adobe Acrobat file - if you don't have the Acrobat Reader, download it from http://www.adobe.com. The full online User Guide manual provides all of the Quick Start Guide information, plus detatiled software operation and maintenance information, plus a glossary of terms and an index.
Registration Card, and return the card by mail. Registration may also be done on Multi-Tech Systems web site at www.multitech.com/register. Opening the packaged program constitutes agreement to be bound by the terms and conditions of this Software License Agreement. Your right to use the software terminates automatically if you violate any part of this software license agreement.
Page 46
PN 82013151 than Customer and his employees and /or agents, without prior written consent from MTS. Customer acknowledges that the techniques, algorithms, and processes contained in the software are proprietary to MTS and Customer agrees not to use or disclose such information except as necessary to use the software.
Page 47
RFIPSC Quick Start Guide prohibited by United States law, including, without limitation, for the development, design, manufacture or production of nuclear, chemical, or biological weapons of mass destruction. Licensee agrees that by purchase and/or use of the Software, s/he hereby accepts and agrees to the terms of this License Agreement.
Page 48
PN 82013151 DAMAGES, INCLUDING CONSEQUENTIAL DAMAGES, WHETHER OR NOT KNOWN TO MULTI-TECH SYSTEMS, INC. IT IS HEREBY EXPRESSLY AGREED THAT LICENSEE’S REMEDY IS LIMITED TO REPLACEMENT OR REFUND OF THE LICENSE FEE, AT THE OPTION OF MULTI-TECH SYSTEMS, INC., FOR DEFECTIVE DISTRIBUTION MEDIA. There is no warranty for misused materials. If this package contains multiple media formats (e.g., both 3.5"...
Page 49
Thank you for purchasing software from Multi-Tech Systems. Choose one of the following options to register your software: By Mail: Complete the registration form and mail. By Fax: Fax this completed registration card to: (763) 785-9874 Via the W www.multitech.com/register Date Purchased: ___/___/___ Prod uct __________________________ Software Serial Number ___________________ Version...
Page 51
By Mail: Complete the registration card, affix postage and mail. By Fax: Fax this completed registration card to: + (763) 785-9874 Via the Web: www.multitech.com/register Date Purchased: ___/___/___ Product ________________________________ Software Serial Number ___________________...