R3721-F3210-F3171-HP High-End Firewalls VPN Configuration Guide-6PW101
377
Figure 270 Network diagram
NOTE:
Before performing the following configurations, make sure that:
• The SSL VPN gateway, the CA, and the hosts used by remote users can reach each other.
• The CA is enabled with the CA service and can issue certificates to the SSL VPN
g
ateway and the hosts.
• The RADIUS server is properly configured to provide normal authentication function for users. In this
example, you need to configure the shared key as expert, confi
g
ure the user account and user
g
roup
information, and add users to user group user_gr2.
Configuring the SSL VPN service
1. Request a certificate for the SSL VPN gateway:
# Configure a PKI entity named en.
a. Select VPN > Certificate Management > Entity from the navigation tree.
b. Click Add to add a PKI entity.
Figure 271 Configuring a PKI entity named en