Next: Verifying Connection Security
Up: Configuring SafeNET SoftRemote/LT v9.0.1
Previous: Configuring SafeNET SoftRemote/LT v9.0.1
Contents
Creating a Road Warrior-to-Gateway Connection
- From the Start Menu of the Windows client, select Programs,
SoftRemoteLT, Security Policy Editor.
- The Security Policy Editor menu will appear. From the tool-bar
select Options.
- From the Options menu choose Certificate Manager.
- The Certificate Manager window will appear. In the current
tab, My Certificates, click the Import Certificate button.
- Select the Browse button from the Import Personal Certificate
menu, to search for the PKCS#12 Certificate. Make certain under the
File of Type pull-down menu Personal Certificate (PKCS12)(*.p12)
is selected. Once the file has been located click Open.
- On the Import Personal Certificate menu make certain the PKCS#12
Personal Certificate check-box is selected under the Import
Type.
- Enter the password used when the certificate was created into the
Password field and click the Import button.
- You will be prompted to verify the certificate. Click Yes.
- The certificate will now be listed in the My Certificates tab
of the Certificate Manager.
- From the Certificate Manager menu select the Root CA
Certificate tab and click the Import Certificate... button.
- Under the Files of Type pull-down menu choose Binary
certificate files (*.der) in the Import CA Certificate menu.
- Browse to where the saved certificate is, select the certificate and
click Import.
- Click the Close button after adding these certificates.
- From the Security Policy Editor window click Edit from
the tool-bar, then select Add and Connection.
- Rename the new connection to an appropriate name such as in the example
below. When new connection is first created you have the option to
rename it. To change it later select Edit from the tool-bar
and then click Rename.
- Under Connection Security, select Secure.
- Confirm the Only Connect Manually checkbox is not checked.
- Under Remote Party Identity and Address, from the ID
Type pull-down select Distinguished Name.
- Click the Edit Name... button.
- Fill in the Edit Distinguished Name fields with the CA Certificate
from the Guardian Digital VPN server that was imported earlier.
- Next the IP Address of the Guardian Digital VPN server needs to be
entered in to the IP Address field located next to the Edit
Name... button.
- Confirm the Protocol field is set to All.
- Make certain the Connect Using checkbox is not checked
and the entire field is grayed out.
- Expand the new connection that was just created in the Network
Security Policy section by clicking on the '+' next to the name.
- Two options will appear. Select My Identity by clicking on
it once.
- Under Select Certificate found in the My Identity portion
of the right-side window, select from the pull-down menu the certificate
that was imported earlier.
- From the ID Type pull-down menu Distinguished Name should
be selected. The fields around it should be grayed out and filled
in with information from the certificate.
- In the Internet Interface pull-down make sure Any is
selected. This will gray out the other fields in this section.
- From the Network Security Policy window select the second option
below the new connection, Security Policy.
- Under Select Phase 1 Negotiation Mode, select Main Mode.
- Check the Enable Perfect Forward Secrecy (PFS) box.
- From the PFS Key Group pull-down menu select Diffie Hellman
Group 2.\
- Remove the check from Enable Replay Detection.
- In Network Security Policy expand the Security Policy
by clicking the '+', then expand Authentication (Phase 1),
and highlight Proposal 1.
- For the Authentication Method choose RSA Signatures.
- Under Encryption and Data Integrity Algorithms, for Encrypt
Alg, choose Triple DES.
- Select SHA-1 for the Hash Alg.
- Under SA Life, choose Seconds, and enter 300
(5 minutes) for the number of seconds.
- Lastly select Diffie-Hellman Group 2 from the Key Group
pull-down menu.
- Returning to the Network Security Policy window, expand Key
Exchange (Phase 2) by clicking the '+', and highlight Proposal
1.
- In the IP Sec Protocols section, select Seconds from
the SA Life pull-down, enter 300 in the Seconds
field and select None for Compression.
- Check Encapsulation Protocol (ESP) next.
- For Encrypt Alg. select Triple DES.
- Select SHA-1 for Hash Alg.
- From the Encapsulation pull-down menu select Tunnel.
- Uncheck Authentication Protocol (AH).
- The settings are now all configured for this connection. Go to the
File menu on the tool bar and select Save.
Subsections
Next: Verifying Connection Security
Up: Configuring SafeNET SoftRemote/LT v9.0.1
Previous: Configuring SafeNET SoftRemote/LT v9.0.1
Contents
docs@guardiandigital.com
2003-09-09