QuadroFXO Manual II: Administrator's Guide
Administrator’s Menus
QuadroFXO; SW Version 5.1.x
71
Please Note:
A pair of keys will always be generated, a public one and a private one. The previously generated pair of keys will become invalid as
well as all existing IPSec connections that use RSA keying.
The IPSec Configuration link refers to the page where IPSec connections can be created and managed.
The IPSec Configuration page consists of two sub-pages: Connection and RSA Key Management.
The Connection sub-page provides an overview of all existing IPSec connections characterized by their Connection Name, the Remote Gateway
(the IP address or the hostname of the IPSec connection partner), the State of the IPSec connection (Stopped, Connecting, Activated, Waiting or
Connected) and the dedicated Keying Type (the encryption type). The content of the table can be sorted in ascending or descending order by
clicking on the header of the respective column. There is a checkbox for every IPSec connection to select it for further editing.
Start activates the connection establishment of the selected
IPSec connection. The State of the IPSec connection will
change into “Connected” or “Activated” depending on the IPSec
connection type. If no record is selected, the error message
“One Record should be selected” appears.
Attention:
It is not recommended to simultaneously start a
static and a dynamic connection configured to use the same
secret key. A dynamic connection may capture the static
connection peer and vice versa, depending on which connection
established first.
Stop disconnects the selected IPSec connection. The state of
the IPSec connection will change into “Stopped”. If no record is
selected, the error message “One Record should be selected”
will appear. More than one record may be selected at a time to
be stopped.
Fig. II-123: IPSec Connection Settings page
Add leads to the Add IPSec Connection wizard where a new IPSec connection can be defined and specified. The wizard provides several pages.
Edit leads to a set of IPSec Connection Properties pages to modify the parameters of the selected IPSec connection. The page includes the same
components as the Add IPSec Connection page. To operate with Edit, only one record may be selected, otherwise an error message “One row
must be selected” appears.
Restart all Connections restarts all active IPSec connections. The State of these IPSec connections will turn into Connected or Activated if the
restart procedure has been successfully completed.
The first IPSec Connection Wizard page Add IPSec Connection has the Connection Name text field that requires a new mandatory IPSec
connection name. If the text field is not filled in, the error message otherwise an error will occur “Error: Incorrect connection name” will appear.
Please Note:
The input in the Connection Name field should only be in Latin characters, otherwise an error occurs and IPSec connection cannot be
created.
The Peer type drop down list is used to choose the remote
machine type for the IPSec Connection to be established. If the
list does not include the required type of machine, choose
Other.
The VPN Network Topology drop down list allows you to select
the location of the peers participating to the VPN connection.
The following options are present in the list:
•
Quadro<>Peer – direct connection between Quadro and a
peer.
•
Quadro<>[Internet]<>Peer – connection between Quadro
and peer over Internet.
•
Quadro<>NAT<>[Internet]<>Peer – connection between
Quadro and peer over Internet through Quadro provider’s
NAT.
•
Quadro<>[Internet]<>NAT<>Peer – connection between
Quadro and peer over Internet through peer provider’s
NAT.
Fig. II-124: IPSec Connection Wizard - Add IPSec Connection
The second page of the IPSec Connection Wizard, IPSec Connection Properties serves to specify the members of the IPSec Connection and to
set the basic parameters for encryption.
A group of radio buttons are used with Dynamic IP/Road
Warrior and Static IP/ Remote Gateway to select if the remote
Quadro (or another VPN gateway device) is connected to the
Internet with a dynamic IP address and is acting as a Road
Warrior, or is connected to the Internet with a fixed IP address
and is acting as a VPN Gateway.
If Dynamic IP / RoadWarrior is selected, the Remote Gateway
IP Address text field will automatically generate the value “any”,
to allow access independent from the sending IP address.
Selecting Static IP / Remote Gateway requires entering the IP
address or the hostname of the remote Quadro (or another VPN
gateway device) in the Remote Gateway text field.
Fig. II-125: IPSec Connection Wizard -IPSec Connection Properties