Using the Web Browser Interface for Advanced Configuration Tasks
Enabling Xauth
Xauth allows IKE to request authentication information from remote users in
between establishing the IKE SA and the IPSec SA. (This authentication
information is different from the authentication method configured for IKE
phase 1; it is individual to each user.) Xauth is typically used for increased
security in client-to-site VPNs. Indeed, the VPN wizard will automatically
prompt you to enable Xauth when you select mobile peers, as discussed in
"Extended Authentication (Client-to-site VPN Only)" on page 16-93.
You can also use Xauth in a site-to-site VPN. Some gateway devices, including
ProCurve Secure Routers, can act as Xauth hosts, which allows the local
router to request authentication from the remote gateway device itself.
Figure 16-91. Enabling AAA from the Passwords Window
To enable Xauth:
1.
Select Passwords under System in the left navigation bar.
2.
In the Service Authentication window, click the AAA Mode Enabled box.
Setting Up Virtual Private Networks
16-119
Need help?
Do you have a question about the 7102dl - ProCurve Secure Router and is the answer not in the manual?
Questions and answers