Cisco Small Business RV 120W Wireless-N VPN Firewall ...

Cisco Small Business RV 120W Wireless-N VPN Firewall ... Cisco Small Business RV 120W Wireless-N VPN Firewall ...

ipland.com.ua
from ipland.com.ua More from this publisher
12.07.2015 Views

Configuring Virtual Private Networks (VPNs) and SecurityConfiguring Security5To configure VPN passthrough:STEP 1STEP 2Choose VPN > IPsec > VPN Passthrough.Choose the type of traffic to allow to pass through the router:• IPsec—Check Enable to allow IP security tunnels to pass through the router.• PPTP—Check Enable to allow Point-to-Point Tunneling Protocol tunnels topass through the router.• L2TP—Check Enable to allow Layer 2 Tunneling Protocol tunnels to passthrough the router.STEP 3Click Save.Configuring SecurityThe Cisco RV120W provides several security methods, including certificateauthentication, RADIUS server support, and 802.1x port-based authentication.Using Certificates for AuthenticationThe Cisco RV120W uses digital certificates for IPsec VPN authentication and SSLvalidation (for HTTPS and SSL VPN authentication). You can obtain a digitalcertificate from a well-known Certificate Authority (CA) such as VeriSign, orgenerate and sign your own certificate using functionality available on thisgateway. The gateway comes with a self-signed certificate, and this can bereplaced by one signed by a CA as per your networking requirements. A CAcertificate provides strong assurance of the server's identity and is a requirementfor most corporate network VPN solutions.A self certificate is a certificate issued by a CA identifying your device (or selfsignedif you don't want the identity protection of a CA). To request a selfcertificate to be signed by a CA, you can generate a Certificate Signing Requestfrom the gateway by entering identification parameters and sending to the CA forsigning. Once signed, the CA's Trusted Certificate and signed certificate from theCA are uploaded to activate the self-certificate validating the identity of thisgateway. The self certificate is then used in IPsec and SSL connections with peersto validate the gateway's authenticity.Cisco RV120W Administration Guide 107

Configuring Virtual Private Networks (VPNs) and SecurityConfiguring Security5To configure certificates, choose Security > SSL Certificate. You can choose thefollowing options:Generating New CertificatesOne of the steps in creating a certificate is to generate a certificate request fromthe computer or the device that will be using the certificate. The CertificateSigning Request (CSR) file needs to be submitted to the CA who will thengenerate a certificate for this device.To generate a certificate request:STEP 1STEP 2STEP 3STEP 4STEP 5STEP 6Choose Security > SSL Certificate.Choose Generate a New Certificate.Click Generate Certificate.Enter the name of the certificate request.Enter the subject of the certificate request. The Subject field populates the CN(Common Name) entry of the generated certificate. Subject names are usuallydefined in the following format: CN=, OU=, O=, L=, ST=, C=. For example,CN=router1, OU=my_company, O=mydept, L=SFO, C=US.Choose the Hash Algorithm: MD5 or SHA-1. The algorithm used to sign thecertificate (RSA) is shown.STEP 7 Enter the signature key length, or the length of the signature (512,1024, or 2048).STEP 8STEP 9(Optional) Enter the IP address of the router.(Optional) Enter the domain name of the router.STEP 10 (Optional) Enter the e-mail address of the company contact that is used whengenerating the self certificate request.STEP 11 Click Generate. A new certificate request is created.Importing a Certificate from a FileTo import a certificate from a file (for example, if you have been given a certificatefrom a CA), the file must be on a computer connected to the Cisco RV120W:Cisco RV120W Administration Guide 108

Configuring Virtual Private Networks (<strong>VPN</strong>s) and SecurityConfiguring Security5To configure <strong>VPN</strong> passthrough:STEP 1STEP 2Choose <strong>VPN</strong> > IPsec > <strong>VPN</strong> Passthrough.Choose the type of traffic to allow to pass through the router:• IPsec—Check Enable to allow IP security tunnels to pass through the router.• PPTP—Check Enable to allow Point-to-Point Tunneling Protocol tunnels topass through the router.• L2TP—Check Enable to allow Layer 2 Tunneling Protocol tunnels to passthrough the router.STEP 3Click Save.Configuring SecurityThe <strong>Cisco</strong> <strong>RV</strong><strong>120W</strong> provides several security methods, including certificateauthentication, RADIUS server support, and 802.1x port-based authentication.Using Certificates for AuthenticationThe <strong>Cisco</strong> <strong>RV</strong><strong>120W</strong> uses digital certificates for IPsec <strong>VPN</strong> authentication and SSLvalidation (for HTTPS and SSL <strong>VPN</strong> authentication). You can obtain a digitalcertificate from a well-known Certificate Authority (CA) such as VeriSign, orgenerate and sign your own certificate using functionality available on thisgateway. The gateway comes with a self-signed certificate, and this can bereplaced by one signed by a CA as per your networking requirements. A CAcertificate provides strong assurance of the server's identity and is a requirementfor most corporate network <strong>VPN</strong> solutions.A self certificate is a certificate issued by a CA identifying your device (or selfsignedif you don't want the identity protection of a CA). To request a selfcertificate to be signed by a CA, you can generate a Certificate Signing Requestfrom the gateway by entering identification parameters and sending to the CA forsigning. Once signed, the CA's Trusted Certificate and signed certificate from theCA are uploaded to activate the self-certificate validating the identity of thisgateway. The self certificate is then used in IPsec and SSL connections with peersto validate the gateway's authenticity.<strong>Cisco</strong> <strong>RV</strong><strong>120W</strong> Administration Guide 107

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!