15
Working with VPNs
274
Nokia IP45 Security Platform User’s Guide v4.0
±
When the IP45 is finished connecting, the Status field changes to Connected.
±
The VPN Login Status box remains open until you log off from the VPN site.
Logging Off a VPN Site
You need to manually log off from a VPN site if:
±
You are using IP45 Tele license.
±
The VPN site is a remote access VPN site configured for manual login.
To log off from a VPN site, click
Close
in the VPN Login Status dialog box. All open tunnels
from the IP45 to the VPN site are closed, and the VPN Login Status dialog box closes.
Closing the browser or dismissing the VPN Login Status box also terminates the VPN session
within a short time.
VPN Certificates
A secure means of authenticating the Nokia IP45 security platform to other VPN gateways is a
digital certificate. The Certificate Authority (CA) issues the certificate to entities such as
gateways, users or computers. The entity then uses the certificate to identify itself and provide
verifiable information. For instance, the certificate includes the distinguishing name (DN) of the
entity, as well as the public key (information about itself). After two entities exchange and
validate each other’s certificates, they can begin encrypting information between themselves by
using the public keys in the certificates.
IP45 v4.0 supports establishing certificates-based VPNs with multiple trusted CA. To use this
capability, IP45 must be managed by Smart Center.
Installing a Certificate
Nokia IP45 supports certificates encoded in the PKCS#12 format. You can install the VPN
certificate by:
±
Generating a self-signed certificate—you can generate a self-signed certificate by using the
Certificate wizard, supported by the IP45 GUI. See
“Generating a Self-Signed Certificate”
on page 275.
±
Importing a certificate—importing a certificate from a location. See
“Importing a
Certificate”
on page 277.
Note
The Nokia IP45 security platform supports certificates encoded in the personal information
exchange syntax standard (PKCS) format. The PKCS #12 file must have a .p12 file
extension. If you do not have a PKCS # 12, obtain it from your network security
administrator.