Siemens RUGGEDCOM ROX II User Manual page 509

Cli
Hide thumbs Also See for RUGGEDCOM ROX II:
Table of Contents

Advertisement

RUGGEDCOM ROX II
CLI User Guide
Parameter
rsa-sig { rsa-sig }
rsa-sig-ipsec { rsa-sig-ipsec }
certificate { certificate }
5.
Configure the system identifier by configuring the following parameters:
Parameter
type { type }
value { value }
6.
Configure the next hop to the other system by configuring the following parameters:
Parameter
type { type }
value { value }
7.
Configure the Network Address Translation (NAT) traversal negotiation method by configuring the following
parameters:
NOTE
Using the RFC 3947 negotiation method over draft-ietf-ipsec-nat-t-ike-02 may cause issues when
connecting to the IPsec server, as RFC 3947 uses different identifiers when NAT is involved. For
example, when a Windows XP/2003 client connects, Openswan reports the main mode peer ID
as ID_FQDN: '@example.com'. However, when a Vista, Windows 7 or other RFC 3947 compliant
client connects, Openswan reports the main mode peer ID as ID_IPV4_ADDR: '192.168.1.1'. If
possible, use the draft-ietf-ipsec-nat-t-ike-02 method to avoid this issue.
Parameter
nat-traversal-negotiation { nat-traversal-negotiation }
Configuring the Connection Ends
Description
Default: none
Key type.
The RSA signature key name.
Synopsis: A string 1 to 8192 characters long
The RSA signature in IPsec format.
The selected certificate.
Description
Synopsis: { default, none, from-certificate, address, hostname,
der-asn1-dn, user-fqdn }
Default: default
The system identifier type. The default value is 'left side public-ip'
unless overwritten by the default connection setting.
Synopsis: A string 1 to 1024 characters long
The hostname, IP address or the Distinguished Name in the
certificate.
Description
Synopsis: { default, default-route, address }
Default: default
The next hop type. The default value is 'right side public-ip'
unless overwritten by the default connection setting.
Synopsis: A string 7 to 15 characters long
The IP address of the next hop that can be used to reach the
destination network.
Description
Synopsis: { default, draft-ietf-ipsec-nat-t-ike-02, rfc-3947 }
Default: default
The NAT traversal negotiation method. Some IPsec endpoints
prefer RFC 3947 over draft-ietf-ipsec-nat-t-ike-02 when
connecting with Openswan, as these implementations use
different identifiers when NAT is involved. For example, when
a Windows XP/2003 client connects, Openswan reports the
Chapter 5
Setup and Configuration
471

Advertisement

Table of Contents
loading

This manual is also suitable for:

Rx1500Rx1512Rx1501Rx1510Rx1511

Table of Contents