Specifications
Explorers Nur für den internen Gebrauch
A31003-H3580-M103-2-76A9, 01-2009
7-48 HiPath 3000/5000 V8 - HG 1500 V8, Administrator Documentation
hg-07.fm
Security
7.2.5.3 IPsec on/IPsec off
You can activate and deactivate the entire VPN functionality. If the VPN folder icon is red, VPN
is off and the IPsec on option is displayed. If the VPN folder icon is green, IPsec is off and the
IPsec off option is displayed.
WBM path:
WBM (write access activated with the Padlock icon in the control area?) > Explorers > Security
> (right-click) VPN > IPsec on
or:
WBM (write access activated with the Padlock icon in the control area?) > Explorers > Security
> (right-click) VPN > IPsec off
A message appears.
Click Activate IPsec or Deactivate IPsec followed by OK in the confirmation mask (save the new
configuration status permanently with the Save icon in the control area). The VPN folder icon
changes color depending on the setting.
7.2.5.4 Reset to insecure mode
You can deactivate all VPN and SSL functions.
All security-specific data (for example, all certificates and services and rules which you created
yourself) is deleted when you disable the VPN and SSL functions and revert to insecure mode.
If you did not save this data previously (see Section 6.1.2.1, "Load from Gateway"), then you
will need to create it again when you later revert to secure mode.
If you deactivate the VPN and SSL functions, the system reverts to the HTTP protocol. The In-
ternet Explorer – which communicates via HTTPS in secure mode – immediately loses access
to the gateway. The connection must be reestablished over the Explorer address bar. Use the
HTTP protocol and port 8085 to do this.
WBM path:
WBM (write access activated with the Padlock icon in the control area?) > Explorers > Security
> (right-click) VPN > Reset to insecure mode
A warning is displayed.
>
You must set at least one "pass" rule between your administration computer’s IP
addresses and the HG 1500 before you activate the IPsec function (see Section
7.2.5.64, "Adding rules"). Otherwise, you cannot access the gateway with WBM after
activation because there is not a single "pass" rule defined in factory mode.