User's Manual Part 2
Table Of Contents
- Chapter 7 Print Server
- Chapter 8 Virtual Private Networking
- Overview of FWG114P Policy-Based VPN Configuration
- Using Digital Certificates for IKE Auto-Policy Authentication
- Walk-Through of Configuration Scenarios on the FWG114P
- How to Use the VPN Wizard to Configure a VPN Tunnel
- Netgear VPN Client to FWG114P
- Step-By-Step Configuration of FWG114P Gateway
- Step-By-Step Configuration of the Netgear VPN Client
Reference Manual for the ProSafe Wireless 802.11g Firewall/Print Server Model FWG114P
8-26 Virtual Private Networking
March 2004, 202-10027-01
• Selectors for all IP protocols, all ports, between 10.5.6.0/24 and 172.23.9.0/24, using IPv4
subnets
Scenario 2: FWG114P to FWG114P with Certificates
The following is a typical gateway-to-gateway VPN that uses Public Key Infrastructure x.509
(PKIX) certificates for authentication. The network setup is identical to the one given in scenario
1. The IKE Phase 1 and Phase 2 parameters are identical to the ones given in scenario 1, with the
exception that the identification is done with signatures authenticated by PKIX certificates.
Note: Before completing this configuration scenario, make sure the correct Time Zone is set on the
FWG114P. For instructions on this topic, please see, “Setting the Time Zone” on page 6-13.
1. Obtain a root certificate.
a. Obtain the root certificate (which includes the public key) from a Certificate Authority
(CA)
Note: The procedure for obtaining certificates differs from a CA like Verisign and a CA,
such as a Windows 2000 certificate server, which an organization operates for providing
certificates for its members. For example, an administrator of a Windows 2000 certificate
server might provide it to you via e-mail.
b. Save the certificate as a text file called trust.txt.
2. Install the trusted CA certificate for the Trusted Root CA.
a. Log in to the FWG114P.
b. From the main menu VPN section, click on the CA’s link.
c. Click Add to add a CA.
d. Click Browse to locate the trust.txt file.
e. Click Upload.
3. Create a certificate request for the FWG114P.
a. From the main menu VPN section, click the Certificates link.