Secure Computing SG300 User Manual page 224

Snapgear gateway
Hide thumbs Also See for SG300:
Table of Contents

Advertisement

DNS hostname address to static IP address
DNS hostname address to DNS hostname address
DNS hostname address to dynamic IP address
From the Local address drop-down, select the type of IPSec endpoint this SnapGear
unit has on the interface on which the tunnel is going out. The SnapGear unit can either
have a static IP, dynamic IP or DNS hostname address. If a dynamic DNS service is
to be used or there is a DNS hostname that resolves to the IP address of the port, then
the DNS hostname address option should be selected. In this example, select dynamic
IP address.
From the Remote address drop-down, select the type of IPSec endpoint used by the
remote party. The remote endpoint can have a static IP address, dynamic IP address
or a DNS hostname address. In this example, select the static IP address option.
From the Authentication drop-down, select the type of authentication for the tunnel. The
SnapGear unit supports the following types of authentication:
Preshared Secret is a common secret (passphrase) that is shared between the
SnapGear unit and the remote party.
This authentication method is widely supported, relatively simple to configure, and
relatively secure, although it is somewhat less secure when used with aggressive
mode keying.
RSA Digital Signatures uses a public/private RSA key pair for authentication.
The SnapGear unit can generate these key pairs. The public keys need to be
exchanged between the SnapGear unit and the remote party in order to configure
the tunnel.
This authentication method is not widely supported, but is relatively secure and
allows dynamic endpoints to be used with main mode keying.
x.509 Certificates are used to authenticate the remote party against a Certificate
Authority's (CA) certificate. The CA must have signed the local certificates that
are used for tunnel authentication. Certificates need to be uploaded to the
SnapGear unit before a tunnel can be configured to use them (see Certificate
Management).
This authentication method is widely supported and very secure, however
differering terminology between vendors can make it difficult to set up a tunnel
between a SnapGear unit and an appliance from another vendor. This
authentication method allows dynamic endpoints to be used with main mode
keying.
Virtual Private Networking
218

Hide quick links:

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the SG300 and is the answer not in the manual?

Questions and answers

This manual is also suitable for:

Sg530Sg570Sg575Sg580Sg550Sg560 ... Show all

Table of Contents