Black Box ACS120 User's Guide Page 394

  • Download
  • Add to my manuals
  • Print
  • Page
    / 450
  • Table of contents
  • TROUBLESHOOTING
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 393
Appendix G - IPSEC
394 BLACK BOX ® Advanced Console Server
rightnexthop=10.88.77.66
rightsubnet=192.168.0.0/24
auto=start
# This line is only for RSA signature
rightrsasigkey=0s1LgR7/oUM...
# This line is only for shared secret
authby=secret
If you want to use shared secrets you must insert the following line to the ipsec.secrets file:
10.0.0.1 10.12.12.1 : PSK "secret"
The good part is that this connection descriptor and the secret line can be added to both the
Console Server and the other end. This is the advantage of using left and right instead of using
local remote parameters.
If you give an explicit IP address for left (and left and right are not directly connected), then
you must specify leftnexthop (the router which Console Server sends packets to in order to
get them delivered to right). Similarly, you may need to specify rightnexthop (vice versa).
The nexthop parameters are needed because of an unfortunate interaction between FreeS/
WAN and the Linuxkernel routing code. They will be eliminated in a future release.
Setting up RSA authentication keys
To build a connection, the Console Server and the other end must be able to authenticate
each other. For FreeS/WAN, the default is public key authentication based on the RSA algo-
rithm. IPsec does allow several other authentication methods.
Page view 393
1 2 ... 389 390 391 392 393 394 395 396 397 398 399 ... 449 450

Comments to this Manuals

No comments