User Guide

Table Of Contents
Bridge GUI Guide: Security Configuration
132
To delete IPsec peer PSKs:
1 Log on to the Bridge GUI through an Administrator-level
account and select
Configure -> IPsec from the menu on the
left.
2 In the IPsec Settings screen’s Pre-Shared Keys frame:
If you want to delete the PSK for a single or selected
IPsec peers, click to place a checkmark in the box(es)
beside the IP address(es) of the peer(s) for which you
want to delete the PSK(s).
or
If you want to delete all IPsec peer PSKs, click ALL at
the top of the
Pre-Shared Keys list to check all IP
addresses.
Click the
Pre-Shared Keys frame’s DELETE PSK button.
The IP addresses of the IPsec peers whose PSKs are deleted
are removed from the
Pre-Shared Keys list.
4.2.4 IPsec Access Control List
An additional level of security can be provided in the Bridge’s
IPsec implementation via the IPsec ACL.
The function is enabled when at least one ACL entry is
configured. It is disabled by default: no ACL entries are
present.
When the IPsec access control function is enabled, the Bridge
compares the Distinguished Names (DNs) contained in the
X.509 digital certificates of authenticating IPsec peers against
those recorded in the IPsec ACL. If no match is found, access
is denied. If a match is found, access is allowed or denied
according to the ACL entry’s
Access rule.
Figure 4.7.
IPsec ACL
entry frame, all platforms
You can configure up to 100 IPsec ACL entries to be applied in
the specified priority. Settings include:
Name - identifies the ACL entry in the Bridge configuration.
Distinguished Name - specifies the DN pattern against
which those in the X.509 certificates of IPsec peers will be
matched. Each RDN (Relative Distinguished Name) in the
sequence comprising the certificate DN is compared to the
corresponding RDN specified in the IPsec ACL entry. You
can use wildcard characters (
*) in the RDNs that comprise
the
Distinguished Name specified for an ACL entry.
For example, the DN pattern:
C=US, ST=Florida, O=*