NetVanta 2000 Series System Manual
Section 4, User Interface Guide
61200361L1-1E
© 2002 ADTRAN, Inc.
71
S
OURCE
A
DDRESS
- Drop down menu allows you to configure the source IP address of the outbound
network traffic for which this VPN policy will provide security. Mostly, this address will be from your
corporate network address space. All entries in the IP Address Table appear in this drop down menu. You
can choose one of these, or select
O
THER
option from this menu and define the source IP address/subnet in
the immediately following text boxes.
A
NY
option in this menu represents all valid IP addresses in the
Internet address space.
D
ESTINATION
A
DDRESS
- Drop down menu allows you to configure the destination IP address of the
outbound network traffic for which this VPN policy will provide security. Mostly, this address will be from
remote site's corporate network address space. All entries in the IP Address Table appear in this drop down
menu. You can choose one of these, or select
O
THER
option from this menu and define the destination IP
address/subnet in the immediately following text boxes.
A
NY
option in this menu represents all valid IP
addresses in the Internet address space.
S
OURCE
P
ORT
- Drop down menu allows you select the source port value for this VPN policy selector. All
entries in the Services table appear in this menu. You can choose one from these, or select
O
THER
option
and define the Source Port in the immediately following text box.
A
NY
option in this menu indicates the
complete port range i.e. 1 to 65535.
D
ESTINATION
P
ORT
- Drop down menu allows you select the destination port value for this VPN policy
selector. All entries in the Services table appear in this menu. You can choose one from these, or select
O
THER
option and define the Destination Port in the immediately following text box.
A
NY
option in this
menu indicates the complete port range (i.e., 1 to 65535).
> P
OLICIES
> VPN > C
ERTIFICATES
The NetVanta 2000 series supports the use of both RSA and DSS Signature Algorithm Certificates. The
NetVanta 2000 series provides the capability to generate self-certificate requests, and maintains a listing of
private keys (certificate requests) that currently have no public key (self-certificate assigned by the
Certificate Authority).
Always contact your Certificate Authority (VeriSign, Entrust, etc.) before generating your self-certificate
request. The parameters configured in your request must match what the Certificate Authority requires for
you to receive your self-certificate. Once the request is generated, follow your Certificate Authority’s
guidelines for supplying them with your request. Many Certificate Authorities allow e-mail requests, but
some do not.
> P
OLICIES
> VPN > C
ERTIFICATES
> S
ELF
C
ERTIFICATE
The NetVanta 2000 series provides the capability to generate self certificate requests in PEM (Privacy
Enhanced Mail) format for either RSA or DSS signature algorithms. Refer to DLP-017,
Generating a
Self-Certificate Request
for more details.
> P
OLICIES
> VPN > C
ERTIFICATES
> CA C
ERTIFICATE
The NetVanta 2000 series supports loading Certificate Authority certificates in PEM (Privacy Enhanced
Mail) format for either RSA or DSS signature algorithms. Refer to DLP-018,
Uploading a CA Certificate
to the NetVanta
for more details.