Manual
Table Of Contents
- Chapter 1 Accessing the Web User Interface
- Chapter 2 Cellular Connections
- Chapter 3 Web User Interface
- 3.1 Web User Interface Introduction
- 3.2 Status Tab
- 3.3 Admin Tab
- 3.4 Network Tab
- 3.5 Services Tab
- 3.6 Automation Tab
- 3.7 Advanced Tab
- Chapter 4 Red Lion Support
- Chapter 5 Compliance Statements & User Information
- Chapter 6 Licensing & Warranty
- Chapter 7 Appendices
Software User Guide 106
Services Tab
EnableSSL:SelectYestoconfigureSSLclient/server.SelectNoandclicktheApplybuttontodisableSSL.
SelectActivityLogLevel:Thiscontrolsthelog ginglevelforSSLConnectionactivity.Therecommendedsettingfora
productionenvironmentisSummary.TherecommendedsettingforatestenvironmentisFull.
Waitfor
Connection(sec.):Time(inseconds)allowedaftersendingSYNpackets,towaitforSYN‐ACK.Therecom‐
mendedsettingforthisfieldis20seconds.
IdleTimeout(min.):Time(inminutes)allowedfornotrafficoveranSSLconnection,beforeclosingdownthelink.The
recommendedsettingis720minutes.
Select
Certificate:Aservercertificatemustbeprovided.Thiswillbeusedtoencryptcommunicationwithallclients.
ThecertificatesmustbeinPEMformat,withanunencryptedkey(notpasswordprotectedwhengenerated).Self
signedcertificatesarehighlyrecommended.UseAdmin‐>CertificateManagertoinstall/updatecerts.
EnableAdvancedSetup:SelectYes
tomodifyadvancedSSLoptions.
BindInterfaceforacceptingSSLConnections:Thiswillrestricttheencryptedlisteningsockettoallowconnections
comingintothespecifiedinterfaceonly.TherecommendedsettingforthisfieldisAny.
BindInterfaceforoutgoingTCPConnections:Thiswillrestricttheunencryptedsockettoinitiateconnectionsout
the
specifiedinterfaceonly.Specifyinganinterfaceheremayconflictwithpolicyrouting,howeveritmayberequiredina
GRE/VPNorothertunneledenvironment.Pleaseconsultwithanetworkarchitectforadditionalassistance.Therec‐
ommendedsettingforthisfieldisAny.
Ciphers:Thisfieldisalistofopenssl
cipherssupported.Pleaseconsultsupportstaffbeforeattemptingtochange.Ref‐
erenceGoogle:”opensslcipherlist”formoreinformation.Therecommendedsettingsforthisfieldare:RC4‐MD5:RC4‐
SHA:SSLv3.
SelectKeep‐Alivebehavior:ThisoptionenablesTCPKeep‐alivesontheunderlyingsockets.Thefollowingoptionsare
supported:
SelectKeep‐Alive
behavior:ThisoptionenablesTCPKeep‐alivesontheunderlyingsockets.Thefollowingoptionsare
supported:
•None:Keep‐alivesnotused.
• All:Keep‐alivesenabledforallsockets.
• Accept:Keep‐alivesenabledforlisteningserversocketside connectionsonly.Thisappliestothecleartextser verforCli‐
entmodesockets,ortheSSLEncryptedserverforServermodesockets.
•Remote:Keep‐alivesenabledforclientinitiatedsockets.
•Local:
Keep‐alivesenabledforClientconnectionsboundtoalocalIPaddress.
YoumayneedtoadjustthemasterKeep‐alivetimer viaNetwork‐>TCPGlobalSettings‐>TCPKeepAlives.
Note:EnablingTCPkeep‐alivesmaydramaticallyincreasethetotalamountoftrafficfortheaffectedsocket(s)depend‐
ingonthemasterinterval,probeandtimeoutsettings,whichshouldbeconsideredforconnections
usingawireless
(cellular)connectionwithrespecttototaldatausageforthesubscriptedplan.
SSLServerTableProperties:










