CONEL SPECTRE v3 ERT — настройка IPsec туннеля: сертификаты и параметры безопасности [73/136]
Превью страниц
Страница 73 /
136
![CONEL SPECTRE v3 ERT [73/136] Configuration](/views2/1190478/page73/bg49.png)
4. CONFIGURATION
Continued from previous page
Item Description
CA Certificate Certificate for X.509 authentication.
Remote Certificate Certificate for X.509 authentication.
Local Certificate Certificate for X.509 authentication.
Local Private Key Private key for X.509 authentication.
Local Passphrase Passphrase used during private key generation.
Extra Options Specifies the additional parameters of the IPsec tunnel for exam-
ple, secure parameters.
Table 40: IPsec Tunnel Configuration
The IPsec function supports the following types of identifiers (ID) for both sides of the
tunnel, Remote ID and Local ID parameters:
• IP address (for example, 192.168.1.1)
• DN (for example, C=CZ,O=Conel,OU=TP,CN=A)
• FQDN (for example, @director.conel.cz) – the @ symbol proceeds the FQDN .
• User FQDN (for example, director@conel.cz)
The certificates and private keys have to be in the PEM format. Use only certificates containing
start and stop tags.
The random time, after which the router re-exchanges new keys is defined as follows:
Lifetime - (Rekey margin + random value in range (from 0 to Rekey margin * Rekey Fuzz/100))
The default exchange of keys is in the following time range:
• Minimal time: 1h - (9m + 9m) = 42m
• Maximal time: 1h - (9m + 0m) = 51m
We recommend that you maintain the default settings. When you set key exchange times
higher, the tunnel produces lower operating costs, but the setting also provides less security.
Conversely, when you reducing the time, the tunnel produces higher operating costs, but
provides for higher security.
The changes in settings will apply after clicking the Apply button.
64
Содержание
233- Firmware version
- Used symbols
- Gpl licence
- Contents
- Contents
- List of figures
- List of figures
- List of figures
- List of tables
- List of tables
- Standard equipment
- Optional features
- Basic information
- Advantages in relation to v2 concept
- This configuration manual describes
- Configuration options
- Configuration
- Basic information
- Access to the web configuration
- Access to the web conf
- Preventing the domain disagreement message
- Access to the web conf
- Status
- Mobile connection
- General status
- Status
- Primary lan secondary lan tertiary lan wifi
- Peripheral ports
- System information
- Status
- Status
- Mobile wan status
- Status
- Status
- Status
- Wifi scan
- Status
- Status
- Status
- Network status
- Status
- Status
- Dhcp status
- Status
- Ipsec status
- Dyndns status
- System log
- Status
- Status
- Lan configuration
- Lan configuration
- Configuration
- Configuration
- Configuration
- Configuration
- Configuration
- Configuration
- Configuration
- Vrrp configuration
- Vrrp configuration
- Configuration
- Configuration
- Configuration
- Mobile wan configuration
- Mobile wan configuration
- Connection to mobile network
- Configuration
- Configuration
- Dns address configuration
- Dns address configuration
- Configuration
- Check connection to mobile network configuration
- Check connection to mobile network configuration
- Switch between sim cards configuration
- Switch between sim cards configuration
- Data limit configuration
- Data limit configuration
- Configuration
- Configuration
- Pppoe bridge mode configuration
- Pppoe bridge mode configuration
- Configuration
- Configuration
- Configuration
- Pppoe configuration
- Pppoe configuration
- Configuration
- Wifi configuration
- Wifi configuration
- Configuration
- Configuration
- Configuration
- Configuration
- Configuration
- Wlan configuration
- Wlan configuration
- Configuration
- Configuration
- Configuration
- Backup routes
- Configuration
- Firewall configuration
- Firewall configuration
- Configuration
- Configuration
- Example of the firewall configuration
- Configuration
- Configuration
- Nat configuration
- Configuration
- Nat configuration
- Configuration
- Configuration
- Configuration
- Configuration
- Openvpn tunnel configuration
- Openvpn tunnel configuration
- Configuration
- Configuration
- Configuration
- Configuration
- Configuration
- Ipsec tunnel configuration
- Ipsec tunnel configuration
- Configuration
- Configuration
- Configuration
- Configuration
- Configuration
- Configuration
- Gre tunnels configuration
- Gre tunnels configuration
- Configuration
- Configuration
- Configuration
- L2tp tunnel configuration
- L2tp tunnel configuration
- Configuration
- Configuration
- Pptp tunnel configuration
- Pptp tunnel configuration
- Configuration
- Configuration
- Dyndns configuration
- Dyndns configuration
- Configuration
- Ntp configuration
- Ntp configuration
- Configuration
- Snmp configuration
- Snmp configuration
- Configuration
- Configuration
- Configuration
- Configuration
- Smtp configuration
- Smtp configuration
- Configuration
- Configuration
- Sms configuration
- Sms configuration
- Configuration
- Configuration
- Sending sms
- Configuration
- Configuration
- Configuration
- Configuration
- Configuration
- Expansion port configuration
- Expansion port configuration
- Configuration
- Configuration
- Configuration
- Configuration
- Usb port configuration
- Usb port configuration
- Configuration
- Configuration
- Configuration
- Configuration
- Startup script
- Configuration
- Up down script
- Configuration
- Configuration
- Automatic update configuration
- Automatic update configuration
- Configuration
- Customization
- User modules
- Customization
- Administration
- Change profile
- Change profile
- Administration
- Set real time clock
- Change password
- Administration
- Unlock sim card
- Set sms service center address
- Administration
- Restore configuration
- Backup configuration
- Backup configuration
- Administration
- Send sms
- Restore configuration
- Update firmware
- Administration
- Reboot
- Administration
- Configuration in typ situations
- Configuration in typ situations
- Access to the internet from lan
- Configuration in typ situations
- Configuration in typ situations
- Backup access to the internet from lan
- Configuration in typ situations
- Configuration in typ situations
- Configuration in typ situations
- Configuration in typ situations
- Secure networks interconnection or using vpn
- Configuration in typ situations
- Serial gateway
- Configuration in typ situations
- Configuration in typ situations
- Glossary and acronyms
- Glossary and acronyms
- Glossary and acronyms
- Glossary and acronyms
- Glossary and acronyms
- Recommended literature
Похожие устройства
-
CONEL CGU 04iИнструкция по эксплуатации -
CONEL CDX 800Инструкция по эксплуатации -
CONEL CDA 70Технические характеристики -
CONEL CDA 70Инструкция по эксплуатации -
CONEL XR5i v2EРуководство по конфигурации -
CONEL XR5i v2EТехнические характеристики -
CONEL XR5i v2EРуководство по подключению -
CONEL XR5i v2EИнструкция по эксплуатации -
CONEL XR5i v2FТехнические характеристики -
CONEL XR5i v2FРуководство по конфигурации -
CONEL XR5i v2FИнструкция по эксплуатации -
CONEL CR10 v2Руководство по подключению
Узнайте, как правильно настроить IPsec туннель, включая сертификаты, ключи и параметры безопасности. Обеспечьте надежную аутентификацию и защиту данных.