138 C
HAPTER
9: C
ONFIGURING
V
IRTUAL
P
RIVATE
N
ETWORK
S
ERVICES
Setting up the
GroupVPN Security
Association
1 Click on VPN onthelefthandsideofthescreenandthenonthe
Summary tab.
a Ensure that the Enable VPN checkbox is ticked.
b Click the Update button to save any changes you have made.
2 Click on the Configure tab.
a Select GroupVPN from the Security Association drop-down box.
b Select IKE using pre-shared secret from the IPSec Keying Mode
drop-down box
c Ensure that the Disable This SA checkbox is not ticked.
3 IfyouwanttouseaRADIUSservertoauthenticateusersticktheRequire
XAUTH/RADIUS checkbox and set up the Firewall for a RADIUS server as
detailed in “Configuring the Firewall to use a RADIUS Server” on
page 132.
4 If you do not have a RADIUS server or do not wish to use your RADIUS
server to authenticate users ensure that the Require XAUTH/RADIUS
checkbox is not ticked.
5 Set the SA Life time (secs) field to 28000.
6 If you want extremely high security select the Strong Encrypt and
Authenticate option from the Encryption Method drop-down box
otherwise select Encrypt and Authenticate.
7 Enteranalphanumericstringofupto30charactersintotheShared
Secret field. As the security of your VPN tunnel depends on the shared
secret pick something that cannot easily be guessed such as a string of
numbers and letters.
8 Click the Export button and save the resulting file to a safe place.
Consider this file as one of the keys to your network and keep it in a safe
and private place.
9 Click the Update button to save the changes you have made.
DUA1611-0AAA02.book Page 138 Thursday, August 2, 2001 4:01 PM
Komentarze do niniejszej Instrukcji