D-Link DFL-1660 User Manual page 385

Network security firewall
Hide thumbs Also See for DFL-1660:
Table of Contents

Advertisement

9.6. CA Server Access
Chapter 9. VPN
As explained previously, the address of the private CA server must be resolvable through public
DNS servers for certificate validation requests coming from the public Internet. If the certificate
queries are coming only from the NetDefend Firewall and the CA server is on the internal side of
the firewall then the IP address of the internal DNS server must be configured in NetDefendOS so
that these requests can be resolved.
Turning Off FQDN Resolution
As explained in the troubleshooting section below, identifying problems with CA server access can
be done by turning off the requirement to validate certificates. Attempts to access CA servers by
NetDefendOS can be disabled with the Disable CRLs option for certificate objects. This means that
checking against the CA server's revocation list will be turned off and access to the server will not
be attempted.
385

Advertisement

Table of Contents
loading

Table of Contents