Download User Manual - Computer Magic

Transcript
IPsec
Setting up Third Party IPsec Clients
With the large number of IPsec servers available, we cannot provide configuration parameters for each device on the market.
The following is the best configuration for allowing a Nitix-powered server to create a virtual
private network (VPN) with third party devices:
Nitix Setup:
•
Remote server: Enter the external IP address of the remote unit.
•
Remote subnet: Enter the internal IP address of the remote unit as well as the subnet. For
example, if the unit’s internal IP address is 192.168.10.1 with a subnet mask of
255.255.255.0, you would enter “192.168.10.0/24”
•
Remote IKE key: Enter your shared key that is being used
•
Was that an RSA public key or a preshared secret key (PSK)?: Select PSK
•
Perfect Forward Secrecy (PFS): Select Yes
Third Party IPsec Client Setup:
•
Encryption / Tunnel: 3DES and MD5
•
Security Association (SA) Lifetime: set to 3600 seconds
•
Mode: If there are different modes available, select Main Mode.
•
Private Key Secret: Use preshared secret keys (PSK), not RSA keys or other keys such
as PKI, as these are not supported on Nitix.
•
Perfect Forward Secrecy: Perfect Forward Secrecy (PFS) must be enabled on both ends
of the connection. The IPsec protocols do not provide a method for the two ends to negotiate this, so you must ensure to set it correctly.
Nitix User Manual – Version 4.1
210