Port Tunnels - Secure Computing SG300 User Manual

Secure computing sg
Hide thumbs Also See for SG300:
Table of Contents

Advertisement

Port Tunnels

Port tunnels are point to point tunnels similar to regular VPNs, but only offer transport for
a TCP service from one end of the tunnel to the other. This allows you to "wrap" a TCP
service, such as telnet or mail retrieval (POP3), in an HTTP or SSL connection. Note that
a single port tunnel may transport a single TCP port only.
The SG unit supports two kinds of port tunnels.
HTTP Tunnels are port tunnels that send data using the HTTP protocol, and are not
encrypted. HTTP tunnels are not encrypted. They can be useful when the SG unit is
behind a firewall that only allows outgoing HTTP connections and blocks all other traffic.
SSL Tunnels are port tunnels that send data using an encrypted SSL pipe. In order to
use an SSL tunnel, you must first install an SSL certificate using the Upload SSL
Certificates page or the Create SSL Certificates page; see the Upload SSL certificates
and Create SSL certificates sections of the chapter entitled Firewall. SSL tunnels can be
useful for encrypting TCP services that are by themselves unencrypted, such as a telnet
or FTP session.
The end of the port tunnel that is offering the TCP service (such as a telnet or FTP
server) must be configured as a Tunnel Server. The end of the port tunnel that is
accessing the TCP service must be configured as a Tunnel Client.
Tunnel server
A tunnel server accepts connections on Tunnel Port from a host on the Internet, and
forwards them over the Data Port to the Data Server.
Click Port Tunnels from the VPN section of the main menu. Select either HTTP Tunnel
Server or SSL Tunnel Server and click Add.
Enter a descriptive Name for this tunnel server. Check Enable.
In Data Server, enter the IP address of the local server that is offering the TCP service,
such as a local mail or FTP server. In Data Port, enter the port on which the TCP
service is running. Incoming requests from hosts on the remote end of the tunnel are
forwarded to this IP address and port.
In Tunnel Port, Enter the TCP port on which to listen for connections from the client.
This must match the tunnel client's Tunnel Port.
The following fields are displayed for HTTP Tunnel Server only:
Virtual Private Networking
237

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sg530Sg550Sg560Sg570Sg575Sg580 ... Show all

Table of Contents