Download User Manual - Computer Magic
Transcript
IPsec Setting up Third Party IPsec Clients With the large number of IPsec servers available, we cannot provide configuration parameters for each device on the market. The following is the best configuration for allowing a Nitix-powered server to create a virtual private network (VPN) with third party devices: Nitix Setup: • Remote server: Enter the external IP address of the remote unit. • Remote subnet: Enter the internal IP address of the remote unit as well as the subnet. For example, if the unit’s internal IP address is 192.168.10.1 with a subnet mask of 255.255.255.0, you would enter “192.168.10.0/24” • Remote IKE key: Enter your shared key that is being used • Was that an RSA public key or a preshared secret key (PSK)?: Select PSK • Perfect Forward Secrecy (PFS): Select Yes Third Party IPsec Client Setup: • Encryption / Tunnel: 3DES and MD5 • Security Association (SA) Lifetime: set to 3600 seconds • Mode: If there are different modes available, select Main Mode. • Private Key Secret: Use preshared secret keys (PSK), not RSA keys or other keys such as PKI, as these are not supported on Nitix. • Perfect Forward Secrecy: Perfect Forward Secrecy (PFS) must be enabled on both ends of the connection. The IPsec protocols do not provide a method for the two ends to negotiate this, so you must ensure to set it correctly. Nitix User Manual – Version 4.1 210