[ Contents] [ Prev] [ Next] [ Index] [ Report an Error]

Applying the Local Digital Certificate to an IPSec Tunnel

You can add a digital certificate to the IPSec tunnel using the J-Web configuration editor or the CLI configuration editor. To apply a certificate to an IPSec tunnel:

  1. Navigate to the top of the configuration hierarchy in either the J-Web or CLI configuration editor.
  2. Perform the tasks described in Table 43.
  3. If you are finished configuring the router, commit the configuration.

Table 43: Applying the Local Digital Certificate to an IPSec Tunnel

Task

J-Web Configuration Editor

CLI Configuration Editor

Navigate to the Services level of the configuration hierarchy.

Use any unique string for the service set name.

  1. In the J-Web interface, select Configuration>View and Edit>Edit Configuration.
  2. Next to Services, click Configure or Edit.
  3. Next to Service set, click Add new entry.
  4. In the Service set name box, type a service set name.

From the [edit] hierarchy level, enter

edit services service-set service-set-name

Configure the IPSec VPN options for the services set.

Use the CA profile you created in Table 38.

  1. Next to Ipsec vpn options, click Configure.
  2. In the Local gateway box, type an IP address.
  3. Next to Trusted ca, click Configure.
  4. In the Trusted ca profile box, type ca-profile-ipsec.
  5. Click OK until you return to the Services page.

Enter

edit services service-set service-set-nameipsec-vpn-options

Enter

set local-gateway ip-address

Enter

set trusted-ca ca-profile-ipsec

Configure the IPSec VPN policy. Use the certificate ID you created in Table 41.

  1. Next to Ipsec vpn, click Configure.
  2. Next to Ike, click Configure.
  3. Next to Policy, click Add new entry.
  4. In the Name box, type the policy name.
  5. In the Local certificate box, type local-verisign.
  6. Click OK.

Return to the [edit services] hierarchy.

Enter

set ipsec-vpn ike policy policy-name local-certificate local-verisign

Configure the IPSec VPN proposal.

  1. Next to Proposal, click Add new entry.
  2. In the Name box, type the proposal name.
  3. From the Authentication method list, select rsa-signatures.
  4. Click OK.

Enter

set ipsec-vpn ike proposalproposal-name authentication-method rsa-signatures


[ Contents] [ Prev] [ Next] [ Index] [ Report an Error]