Netgear SRX5308 Specifications Page 234

  • Download
  • Add to my manuals
  • Print
  • Page
    / 357
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 233
Managing Users, Authentication, and Certificates
234
ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308
4. Click Apply to save your settings.
Manage Digital Certificates
The VPN firewall uses digital certificates (also known as X509 certificates) during the Internet
Key Exchange (IKE) authentication phase to authenticate connecting IPSec VPN gateways
or clients, or to be authenticated by remote entities. The same digital certificates are
extended for secure web access connections over HTTPS (that is, SSL connections).
Digital certificates either can be self-signed or can be issued by certification authorities (CAs)
such as an internal Windows server or an external organizations such as Verisign or Thawte.
However, if the digital certificate contains the extKeyUsage extension, the certificate needs to
be used for one of the purposes defined by the extension. For example, if the digital
certificate contains the extKeyUsage extension that is defined for SNMPV2, the same
certificate cannot be used for secure web management. The extKeyUsage would govern the
certificate acceptance criteria on the VPN firewall when the same digital certificate is being
used for secure web management.
On the VPN firewall, the uploaded digital certificate is checked for validity and purpose. The
digital certificate is accepted when it passes the validity test and the purpose matches its use.
The purpose needs to correspond to its use for IPSec VPN, SSL VPN, or both. If the defined
purpose is for IPSec VPN and SSL VPN, the digital certificate is uploaded to both the IPSec
VPN certificate repository and the SSL VPN certificate repository. However, if the defined
purpose is for IPSec VPN only, the certificate is uploaded only to the IPSec VPN certificate
repository.
The VPN firewall uses digital certificates to authenticate connecting VPN gateways or clients,
and to be authenticated by remote entities. A digital certificate that authenticates a server, for
example, is a file that contains the following elements:
A public encryption key to be used by clients for encrypting messages to the server.
Information identifying the operator of the server.
A digital signature confirming the identity of the operator of the server. Ideally, the
signature is from a trusted third party whose identity can be verified.
Check to Edit Password Select this check box to make the password fields accessible to modify the
password.
Enter Your Password Enter the old password.
New Password Enter the new password.
Confirm New Password Reenter the new password for confirmation.
Idle Timeout The period after which an idle user is automatically logged out of the web
management interface. De default idle time-out period is 10 minutes.
Table 60. Edit User screen settings (continued)
Setting Description
Page view 233
1 2 ... 229 230 231 232 233 234 235 236 237 238 239 ... 356 357

Comments to this Manuals

No comments