Ipsec Failover - Secure Computing SG300 User Manual

Secure computing sg
Hide thumbs Also See for SG300:
Table of Contents

Advertisement

Click Browse to locate the certificate file or files.
If you are adding a Local Certificate, enter the Public Key certificate in Local Certificate
the Local Private Key certificate in Private Key Certificate, and the passphrase to unlock
the private key certificate in Private Key Certificate Passphrase. The certificate must
be in PEM or DER format.
Certificates have time durations in which they are valid. Ensure that the certificates
uploaded are valid and that the Date and Time settings have been set correctly on the
SG unit.

IPSec Failover

Note
SG560, SG565, SG580, SG710 only.
The SG unit can be configured to failover and fallforward between IPSec connections.
Two common scenarios are described below.
The following scenario assumes that the Headquarters SG has two static Internet IP
addresses and the Branch Office SG has a dynamic Internet IP address. The Branch
Office SG establishes an IPSec tunnel to the primary Internet IP address at the
Headquarters SG as the primary IPSec tunnel path. If this IPSec connection is detected
to have failed, a failover IPSec tunnel is established to the secondary Internet IP address
at the Headquarters SG. Once in the failover state, the Branch Office SG will periodically
determine if the primary IPSec tunnel path is functioning again, and if so, will fall forward
to use the primary link instead.
224
Virtual Private Networking

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sg530Sg550Sg560Sg570Sg575Sg580 ... Show all

Table of Contents