Page 271 / 342 Scroll up to view Page 266 - 270
Configuring Route-Based VPNs
Nokia IP45 Security Platform User’s Guide v4.0
271
The VPN Sites page opens with a list of VPN sites.
3.
To delete a VPN site, click the Erase icon, next to the VPN site.
A confirmation message appears.
4.
Click OK.
The VPN site is deleted.
Logging On to a VPN Site
If you chose automatic login, a VPN tunnel is created automatically when you try to access the
VPN site.
If you chose manual login, you need to log on to a VPN site every time you want to access the
VPN site.
You can log on to a VPN site either through the Nokia IP45 GUI or the
my.vpn
page. When you
log on, a VPN tunnel is established. Only the computer from which you logged on can use the
tunnel. To share the tunnel with other computers in your home network, you must log on to the
VPN site from those computers, using the same username and password.
Note
You can use a single username and password for each VPN destination gateway computer.
Page 272 / 342
15
Working with VPNs
272
Nokia IP45 Security Platform User’s Guide v4.0
Logging On from the Nokia IP45 Security Platform GUI
The following sections provide information how to log on to the IP45 security platform by using
GUI.
To log on from IP45 GUI
To log on to a VPN site from the Nokia IP45 GUI, use the following procedure:
1.
Choose VPN from the IP45 main menu.
The VPN Sites page opens, with the list of configured VPN sites.
2.
In the VPN submenu, click VPN Login.
The VPN Login page opens.
3.
Select the site to log on to.
4.
Type your username and password in the appropriate fields.
5.
Click Connect.
±
If the IP45 device is configured to automatically download the network configuration,
the IP45 downloads the network configuration.
±
If you specified a network configuration when you add the VPN site, the IP45 attempts to
create a tunnel to the VPN site.
±
The VPN Login Status dialog box and the Connecting page appears. When the IP45 is
finished connecting, the Status field changes to Connected. The VPN Login Status dialog
box remains open until you log off from the VPN site.
Page 273 / 342
Configuring Route-Based VPNs
Nokia IP45 Security Platform User’s Guide v4.0
273
±
When the IP45 is finished connecting, the status changes to connected.
Logging On Through my.vpn
Use the following procedure to log on through my.vpn:
Note
You do not need to know the my.firewall page administrator's password to use the my.vpn
page.
To log on to a VPN site through the my.vpn page
1.
Go to http://my.vpn.The VPN Login page opens.
2.
Select the site to log on to.
3.
Enter your username and password in the appropriate fields.
4.
Click Login.
±
If the IP45 is configured to automatically download the network configuration, the IP45
downloads the network configuration.
±
When adding the VPN site, if you specified a network configuration, the IP45 attempts to
create a tunnel to the VPN site.
±
The VPN Login Status dialog box appears. The Status field tracks the progress of the
connection.
Page 274 / 342
15
Working with VPNs
274
Nokia IP45 Security Platform User’s Guide v4.0
±
When the IP45 is finished connecting, the Status field changes to Connected.
±
The VPN Login Status box remains open until you log off from the VPN site.
Logging Off a VPN Site
You need to manually log off from a VPN site if:
±
You are using IP45 Tele license.
±
The VPN site is a remote access VPN site configured for manual login.
To log off from a VPN site, click
Close
in the VPN Login Status dialog box. All open tunnels
from the IP45 to the VPN site are closed, and the VPN Login Status dialog box closes.
Closing the browser or dismissing the VPN Login Status box also terminates the VPN session
within a short time.
VPN Certificates
A secure means of authenticating the Nokia IP45 security platform to other VPN gateways is a
digital certificate. The Certificate Authority (CA) issues the certificate to entities such as
gateways, users or computers. The entity then uses the certificate to identify itself and provide
verifiable information. For instance, the certificate includes the distinguishing name (DN) of the
entity, as well as the public key (information about itself). After two entities exchange and
validate each other’s certificates, they can begin encrypting information between themselves by
using the public keys in the certificates.
IP45 v4.0 supports establishing certificates-based VPNs with multiple trusted CA. To use this
capability, IP45 must be managed by Smart Center.
Installing a Certificate
Nokia IP45 supports certificates encoded in the PKCS#12 format. You can install the VPN
certificate by:
±
Generating a self-signed certificate—you can generate a self-signed certificate by using the
Certificate wizard, supported by the IP45 GUI. See
“Generating a Self-Signed Certificate”
on page 275.
±
Importing a certificate—importing a certificate from a location. See
“Importing a
Certificate”
on page 277.
Note
The Nokia IP45 security platform supports certificates encoded in the personal information
exchange syntax standard (PKCS) format. The PKCS #12 file must have a .p12 file
extension. If you do not have a PKCS # 12, obtain it from your network security
administrator.
Page 275 / 342
VPN Certificates
Nokia IP45 Security Platform User’s Guide v4.0
275
Note
To use certificates authentication, each Nokia IP45 security platform should have an unique
certificate. Do not use the same certificate for more than one gateway.
Generating a Self-Signed Certificate
You can now generate self-signed certificate by using http://my.firewall.
To generate a self-signed certificate
1.
Choose VPN from the IP45 main menu and click Certificate.
The VPN Certificate page opens.
2.
Click Install Certificate.
The Certificate wizard opens.
3.
Click Generate a self-signed security certificate for this gateway.
4.
Click Next.

Rate

3.5 / 5 based on 2 votes.

Popular Nokia Models

Bookmark Our Site

Press Ctrl + D to add this site to your favorites!

Share
Top