Advertisement

Quick Links

SSH IPSec Client
Models RFIPSC-1/5/10/50
Quick Start Guide

Advertisement

Table of Contents
loading

Summary of Contents for Multitech ROUTE FINDER RFIPSC-10

  • Page 1 SSH IPSec Client Models RFIPSC-1/5/10/50 Quick Start Guide...
  • Page 3 SSH Communications Security Corp. All products or technologies are the trademarks or registered trademarks of their respective holders. Multi-Tech Systems, Inc. 2205 Woodale Drive Mounds View, Minnesota 55112 (763) 785-3500 or (800) 328-9717 Fax 763-785-9874 Tech Support (800) 972-2439 Internet Address: http://www.multitech.com...
  • Page 5: Table Of Contents

    Contents Chapter 1 – Introduction and Description Introduction ..................Product Description ................Internet Protocol (IP)................Internet Protocol Security (IPSec)............About this Manual and Related Manuals ..........Ship Kit Contents.................. Chapter 2 – SSH IPSec Client Installation and Setup Introduction ..................Pre-Installation Requirements ...............
  • Page 6 Figures Figure Number Title Page Number Figure 1 The SSH Sentinel installation package icon. Figure 2. SSH Sentinel Welcome screen. Figure 3. Licensing Agreement Figure 4. Choose Destination Path. Figure 5. Generating the Authentication Key. Figure 6. Authentication Key Generation Done. Figure 7.
  • Page 7: Chapter 1 - Introduction And Description

    RFIPSC Quick Start Guide Chapter 1 – Introduction and Description Introduction Welcome to Multi-Tech’s new RouteFinder, model RF650VPN. The RF650VPN is an Internet security appliance that lets you use data encryption and the Internet to securely connect to telecommuters, remote offices, customers or suppliers while avoiding the cost of expensive private leased lines.
  • Page 8: Internet Protocol (Ip)

    PN 82013151 Internet Protocol (IP) The open architecture of the Internet Protocol (IP) makes it a highly efficient, cost- effective and flexible communications protocol for local and global communications. IP is widely adopted, not only on the global Internet, but also in the internal networks of large corporations.
  • Page 9: About This Manual And Related Manuals

    RFIPSC Quick Start Guide About this Manual and Related Manuals This Quick Start Guide manual contains four chapters and one appendix, and is intended to provide the experienced client user or system administrator with the information needed to quickly get the SSH IPSec Client software up and running. The full Sentinel SSH IPSec Client User Guide manual is provided on the SSH IPSec Client CD-ROM included in the license pak.
  • Page 10 PN 82013151...
  • Page 11: Chapter 2 - Ssh Ipsec Client Installation And Setup

    RFIPSC Quick Start Guide Chapter 2 - SSH IPSec Client Installation and Setup Introduction This section describes the SSH Sentinel software, an IPSsec client product by SSH Communications Security Corp, providing secure communications over a TCP/IP connection. The Sentinel SSH software is used by client devices for secure connection to the Multi-Tech RouteFinder model RF650VPN.
  • Page 12: Starting The Ssh Sentinel Installation

    PN 82013151 To run the SSH Sentinel client software, you need a personal computer with at least the following configuration: Processor Pentium 100 MHz Memory (RAM) 32 MB for Windows 9x, or 64 MB for Windows NT4/2000 Hard disk space 10 megabytes of free disk space Network connection TCP/IP network protocol Starting the SSH Sentinel Installation The SSH Sentinel installation requires that you have full access rights for the system...
  • Page 13 RFIPSC Quick Start Guide The installer will run Installation Wizard, which creates the initial configuration and sets up the SSH Sentinel client software. Note: If a previous version of the SSH Sentinel software is installed on your computer and you try to install a new version, the wizard updates the software and the steps described here are skipped.
  • Page 14: Authenitcation Key Generation

    PN 82013151 Figure 4. Choose Destination Path. Authentication Key Generation The SSH Sentinel Installation Wizard generates a primary authentication key for IPSec peer (host) authentication purposes. The primary authentication key is a 1024-bit RSA key pair that is used for digital signatures and strong authentication. Authentication key generation begins with random seed generation.
  • Page 15 RFIPSC Quick Start Guide Figure 5. Generating the Authentication Key. Figure 6. Authentication Key Generation Done.
  • Page 16: Identity Information

    PN 82013151 Identity Information 5. SSH Sentinel uses certificates and digital signatures as its primary authentication method. SSH Sentinel processes certificates according to the IETF Public-Key Infrastructure X.509v3 standards, allowing you to take advantage of the public-key infrastructure (PKI). SSH Sentinel supports certificate revocation lists (CRLs) and authority revocation lists (ARLs, that is, CRLs for CAs) and is very configurable.
  • Page 17: Choose The Enrollment Method

    RFIPSC Quick Start Guide Choose the Enrollment Method 6. A certification request can be created as part of the installation process. You can either enroll online, in other words create and send the request immediately, or save the request in a file and deliver it later to the certification authority (CA). If there is no certification authority available or you for some reason want to postpone the creation of the request, create a self-signed certificate.
  • Page 18 PN 82013151 Online Enrollment Information To enroll online, you must locate the certification authority server and you must possess the certification authority certificate. Most often, you can download the certificate of the certification authority from its web site. Figure 9. Online Enrollment Settings You must also specify the enrollment protocol.
  • Page 19 RFIPSC Quick Start Guide either saved it in a file or copied the contents of it to the Windows clipboard. In a file, the certificate may be in binary (X.509), PEM (Privacy Enhanced Mail) or HEX format. Pasted from the clipboard, the certificate must be in PEM encoded format. Advanced button (D) Opens a dialog box for configuring the socks and proxy settings.
  • Page 20: Encryption Speed Diagnostics

    PN 82013151 you may prefer sending the request via email or using an enrollment service on the Web. Select PKCS#10 request file location In the text field (callout A in Figure 10 above), enter the path and the name of the file where the certification request will be stored.
  • Page 21: Completing The Installation

    RFIPSC Quick Start Guide encryption hardware vendors. It has the advantage of giving simple figures on the speed: Due to a number of variables that affect the final result, it would be very complicated to define a standard environment in which to reliably measure the overall network throughput.
  • Page 22: Ssh Ipsec Client Setup

    PN 82013151 SSH IPSec Client Setup The RouteFinder supports VPN (Virtual Private Networking), which provides the ability to encrypt IP network traffic. Host 1 <----> Router <----> Internet <----> Router <----> Host 2 <----------------- encrypted -------------------> All communication between the hosts uses strong encryption, so that nobody is able to listen to this communication.
  • Page 23: Routefinder Configuration

    RFIPSC Quick Start Guide RouteFinder Configuration 1. Define two networks in Definitions Networks DMZ Network 192.168.3.0 255.255.255.0 Sentinel ssh Client 212.6.145.3 255.255.255.255 2. Define and enable the following Packet Filter rules: Sentinel ssh Client DMZ Network Allow DMZ Network Sentinel ssh Client Allow The first rule allows the Sentinel SSH Client to initiate connections to the DMZ Network.
  • Page 24: Sentinel Configuration

    PN 82013151 Sentinel Configuration 4. From the Control panel select the Sentinel Policy Editor 5. At select Key Management Authentication Keys 6. Click...
  • Page 25 RFIPSC Quick Start Guide 7. Click to create a new Authentication Key. 8. Check the and click Create new preshared key checkbox...
  • Page 26 PN 82013151 9. Select a Primary Identifier from the drop down list. Select Primary Identifier Select a and click Host IP Address 10. Enter the and click Preshared Key Information...
  • Page 27 RFIPSC Quick Start Guide 11. Select and click VPN Connection...
  • Page 28 PN 82013151 12. Select the information and click Note Security Gateway Intranet IP Address that the System routing is set automatically. The RouteFinder looks for Subnet Mask that you entered. Intra IP Address If the that you entered is not found, the Intra IP Address Probe Results unsuccessful...
  • Page 29 RFIPSC Quick Start Guide 13. Click screen is displayed. Details>> Connection Properties General 14. Edit the and the then change the IP Address Settings Proposal Parameters Rule (if necessary). Click Comment...
  • Page 30 PN 82013151 15. Click on the tab. Advanced 16. As necessary, edit the Advanced Options NAT Traversal Virtual IP Address Settings and/or check the check box and click Enable Extended Authentication The Probe Results screen displays.
  • Page 31 RFIPSC Quick Start Guide 17. Click Details>>...
  • Page 32 PN 82013151 18. Verify the connection details information and click Close...
  • Page 33 RFIPSC Quick Start Guide The Security Policy begins updating. 19. When the Security Policy is done updating, click to Ping the new Diagnostics ... connection.
  • Page 34 PN 82013151 If the ping is successful, the Host to NET using SSH Sentinel 1.1.1 (static IP) to connect to a RouteFinder using Pre Shared Keys (PSK) process is complete.
  • Page 35: Ssh Sentinel Installation Notes

    RFIPSC Quick Start Guide SSH Sentinel Installation Notes SSH Sentinel supports Microsoft Windows 95/98, Windows Me, Windows NT 4.0 and Windows 2000. The SSH Sentinel software download site is at http://www.ssh.com/products/sentinel/beta/. Start the SSH Sentinel setup program ( ) by double clicking the icon and Sentinel.exe follow instructions on the screen.
  • Page 36: Updating Ssh Sentinel

    PN 82013151 Updating SSH Sentinel If you launch the installation package with a previous version of SSH Sentinel software on your computer, the existing version is automatically updated. The contents (i.e., the policies, the rules, the authentication keys, etc.) are preserved. Only the software version is updated.
  • Page 37: Chapter 3 - Service, Warranty And Tech Support

    On-line Warranty Registration If you would like to register your RouteFinder electronically, you can do so at the following address: http://www.multitech.com/register/ Tech Support. Multi-Tech has an excellent staff of technical support personnel available to help you get most out of your Multi-Tech product. If you have any questions about the operation of this unit, call 1-800-972-2439.
  • Page 38: Recording Routefinder Information

    _______________________________________________________________ Contacting Tech Support via E-mail If you prefer to receive technical support via the Internet, you can contact Tech Support via e-mail at support@multitech.com or from http://www.multitech.com/ . When responding to e-mails from our technical staff please attach all previous e-mails to assist us in giving you a speedy response.
  • Page 39: Service

    Multi-Tech’s presence includes a Web site at http://www.multitech.com and an ftp site at ftp://ftp.multitech.com. Ordering Accessories SupplyNet, Inc. supplies replacement transformers, cables and connectors for select Multi-Tech products. You can place an order with SupplyNet via mail, phone, fax or the Internet at: Mail: SupplyNet, Inc.
  • Page 40 PN 82013151 SupplyNet On-line Ordering Instructions 1. Browse to http://www.thesupplynet.com. In the drop-down Browse by Manufacturer list, select and click Multi-Tech 2. To order, type in the quantity, and click Add to Order 3. Click to change your order. Review Order 4.
  • Page 41: Appendix A - Rfipsc-1/5/10/50 Client Software Cd

    RFIPSC Quick Start Guide Appendix A - RFIPSC-5/10/50 Client Software CD The RouteFinder RFIPSC-5/10/50 CD contains the SSH Sentinel IPSec Client files as shown below. When you insert the CD in your computer's CD-ROM drive, the SSH Sentinel IPSec Client software Install screen displays.
  • Page 42 PN 82013151 Click Install IPSEC Client Software to load the SSH Sentinel IPSec Client Software and either run the program from the CD or save it to your computer's hard disk drive (the initial screen is shown below). Click Read the End User Licensing Agreement to view the Multi-Tech Multi-User Software License Agreement (the initial screen is shown below).
  • Page 43 (this document). You can also find it directly on the CD in Acrobat format (InstallationGuide.pdf), as well as on the Multi-Tech web site (http://www.multitech.com). This is an Adobe Acrobat file - if you don't have the Acrobat Reader, download it from http://www.adobe.com. The full online User Guide manual provides all of the Quick Start Guide information, plus detatiled software operation and maintenance information, plus a glossary of terms and an index.
  • Page 44 PN 82013151...
  • Page 45: Appendix B - Multi-User Software License Agreement

    Registration Card, and return the card by mail. Registration may also be done on Multi-Tech Systems web site at www.multitech.com/register. Opening the packaged program constitutes agreement to be bound by the terms and conditions of this Software License Agreement. Your right to use the software terminates automatically if you violate any part of this software license agreement.
  • Page 46 PN 82013151 than Customer and his employees and /or agents, without prior written consent from MTS. Customer acknowledges that the techniques, algorithms, and processes contained in the software are proprietary to MTS and Customer agrees not to use or disclose such information except as necessary to use the software.
  • Page 47 RFIPSC Quick Start Guide prohibited by United States law, including, without limitation, for the development, design, manufacture or production of nuclear, chemical, or biological weapons of mass destruction. Licensee agrees that by purchase and/or use of the Software, s/he hereby accepts and agrees to the terms of this License Agreement.
  • Page 48 PN 82013151 DAMAGES, INCLUDING CONSEQUENTIAL DAMAGES, WHETHER OR NOT KNOWN TO MULTI-TECH SYSTEMS, INC. IT IS HEREBY EXPRESSLY AGREED THAT LICENSEE’S REMEDY IS LIMITED TO REPLACEMENT OR REFUND OF THE LICENSE FEE, AT THE OPTION OF MULTI-TECH SYSTEMS, INC., FOR DEFECTIVE DISTRIBUTION MEDIA. There is no warranty for misused materials. If this package contains multiple media formats (e.g., both 3.5"...
  • Page 49 Thank you for purchasing software from Multi-Tech Systems. Choose one of the following options to register your software: By Mail: Complete the registration form and mail. By Fax: Fax this completed registration card to: (763) 785-9874 Via the W www.multitech.com/register Date Purchased: ___/___/___ Prod uct __________________________ Software Serial Number ___________________ Version...
  • Page 50 PN 82013151...
  • Page 51 By Mail: Complete the registration card, affix postage and mail. By Fax: Fax this completed registration card to: + (763) 785-9874 Via the Web: www.multitech.com/register Date Purchased: ___/___/___ Product ________________________________ Software Serial Number ___________________...
  • Page 52 PN 82013151...
  • Page 53 RFIPSC Quick Start Guide...
  • Page 54 PN 82013151 82013151 (B)

Table of Contents