Quick Reference Guide
ProSafe VPN Firewall 50 FVS338 Reference Manual
Virtual Private Networking 5-27
v1.0, January 2010
• IPSec Host. If you want authentication by the remote gateway, enter a user name and
password to be associated with this IKE policy. If this option is chosen, the remote gateway
must specify the user name and password used for authenticating this gateway.
.
Configuring XAUTH for VPN Clients
Once the XAUTH has been enabled, you must establish user accounts on the local database to be
authenticated against XAUTH, or you must enable a RADIUS-CHAP or RADIUS-PAP server.
To enable and configure XAUTH:
1. Select VPN from the main menu and Policies from the submenu. The IKE Policies screen will
display.
2. You can either modify an existing IKE policy by clicking edit adjacent to the policy, or create
a new IKE Policy by clicking add. (Figure 5-28 on page 5-28 shows the Add IKE Policy
screen.)
Note: If a RADIUS-PAP server is enabled for authentication, XAUTH will first check the
local User Database for the user credentials. If the user account is not present, the
VPN firewall will then connect to a RADIUS server.
Note: If you are modifying an existing IKE policy to add XAUTH, if it is in use by a
VPN policy, the VPN policy must be disabled before you can modify the IKE
policy.
Figure 5-27