Apple Xserve Up Mac OS X Server Specifications Page 246

  • Download
  • Add to my manuals
  • Print
  • Page
    / 329
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 245
246 Chapter 14 Configuring and Managing Network Services
The s2svpnadmin tool can:
 List configured site-to-site VPN servers
 Display their configuration details
 Add a configuration
 Delete a configuration
You can use this tool to configure a local VPN server, not a remote one. To set up a site-
to-site server, you must configure the two VPN gateway servers at the two sites
independently.
You must run s2svpnadmin with root privileges.
Configuring Site-to-Site VPN
To configure a site-to-site VPN, run s2svpnadmin with root privileges, choose the
“Configure a new site-to-site server option, and provide the following information:
 A configuration name used to identify the server. Do not include spaces in it.
 The external gateway address of the local site.
 The external gateway address of the remote site.
 The form of IPSec security to use (certificate or shared-secret). Before choosing
certificate-based authentication, be sure that at least one certificate is installed on
the server.
s2svpnadmin displays a list of installed certificates and prompts the user to choose
one.
Certificates can be created, self-signed, and installed using Server Admin. To use a
shared secret, be sure the same shared secret is configured on the VPN server at the
other site.
 Policies consisting of local and remote subnet addresses. A policy includes a local
network and a remote network. A network is specified by a network address and the
number of prefix bits that must be masked in an IPv4 address to determine the
network address it corresponds to. Be sure that a compatible policy is configured on
both VPN servers.
If you make an invalid entry, s2svpnadmin forces you to start over again.
Note: s2svpnadmin prompts if the server must be enabled. By default, it is enabled.
s2svpnadmin does not support editing a configuration, so if the server is not enabled,
you must delete the configuration and then recreate it and enable it later. Alternatively,
you can edit the configuration file. The configuration file is a plist file in /Library/
Preferences/SystemConfiguration/com.apple.RemoteAccessServers.plist.
Page view 245
1 2 ... 241 242 243 244 245 246 247 248 249 250 251 ... 328 329

Comments to this Manuals

No comments