R3721-F3210-F3171-HP High-End Firewalls VPN Configuration Guide-6PW101

377
Figure 270 Network diagram
NOTE:
Before performing the following configurations, make sure that:
The SSL VPN gateway, the CA, and the hosts used by remote users can reach each other.
The CA is enabled with the CA service and can issue certificates to the SSL VPN
g
ateway and the hosts.
The RADIUS server is properly configured to provide normal authentication function for users. In this
example, you need to configure the shared key as expert, confi
g
ure the user account and user
g
roup
information, and add users to user group user_gr2.
Configuring the SSL VPN service
1. Request a certificate for the SSL VPN gateway:
# Configure a PKI entity named en.
a. Select VPN > Certificate Management > Entity from the navigation tree.
b. Click Add to add a PKI entity.
Figure 271 Configuring a PKI entity named en