Chapter 11 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -Configuration parameters - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Chapter 11
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - 261 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
•
Tunnel mode:
Use this mode if you want to create a secure tunnel to a remote peer in
order to transfer data between two networks (i.e. both peers are operating as
gateways). This option can also be used in peer-to-peer mode by selecting the
appropriate options for
Incoming traffic
and
Outgoing traffic
.
•
Transport mode:
This option creates a point-to-point connection to a remote peer.
Use this option if only the CN3000 needs to communicate with the remote peer.
Interface
Select the port that the policy applies to.
Encryption algorithm
Select the encryption algorithm used for this policy.
Perfect Forward Secrecy
Enable this option to support automatic regeneration of keys. The key is changed
according to the following intervals:
• Phase 1 exchange: key changed every 6 hours
• Phase 2 exchange: key changed every 1 hour
Note: The CN3000 will negotiate times up to 24 hours as required by the peer.
Peer
Accept any peer
(only available in tunnel mode)
Enable this option to permit the policy to accept an IPSec security association from any
peer. When this option is enabled, the CN3000 sets
ID type
and
ID
automatically based
on the selection for
Authentication method
. See IKE options for more information.
Address
Specify the IP address or domain name of the peer.
ID type
Specify the method used to identify the peer.
IP address
Specify the peer’s IP address. If you are using a
Preshared key
for
Authentication
method
, then you must use this option.
FQDN
Specify a fully qualified domain name. For example: gateway.mycompany.com
user@FQDN
Specify a fully-qualified user name. For example: fred@mycompany.com
DER_ASN1_DN
Specify a distinguished name (DN) in LDAP (X.501) format. Enter a maximum of 91
characters. The following fields are supported.
Separate fields by a comma, space, or a forward slash (/). For example:
Field
Description
CN
SN
C
L
ST
O
OU
G
E
commonName
serialNumber
countryName
localityName
stateOrProvinceName
organizationName
organizationalUnitName
givenName
emailAddress
Summary of Contents for CN3000
Page 1: ...CN3000 Administrator s Guide...
Page 8: ...Table of Contents 8...
Page 60: ...Chapter 2 How it works Chapter 2 60...
Page 94: ...Chapter 4 Scenarios Chapter 4 94...
Page 106: ...Chapter 5 Activating the public access interface Chapter 5 106...
Page 211: ...Chapter 10 SSL certificates Chapter 10 211...
Page 292: ...Chapter 13 The configuration file Chapter 13 292...
Page 370: ...Chapter 16 Sample setup Microsoft RADIUS Chapter 16 370...
Page 396: ...Chapter 16 Sample setup Microsoft RADIUS Chapter 16 396...
Page 414: ...Chapter 17 Experimenting with NOC authentication Chapter 17 414...