description.txt
来自「ipsec vpn」· 文本 代码 · 共 19 行
TXT
19 行
The purpose of this test case is to demonstrate how to setup road warrioraccess using XAUTH+self-signed certificates.The intent is to use RSA signatures and Main Mode for phase 1.XAUTH provides the authentication for phase 2.The initial policy is that of opportunistic encryption - a random clientconnects for phase 1, however it offers XAUTHInitRSA as the method.The gateway does not have the client's key. In this test case, it issent by self-signed certificate payload. This completes phase 1.The client already has the gateway's certificate, pre-configured or retrievedby DNS. (KEY, IPSECKEY or CERT). This uni-directional authentication willdetect a MITM that is done at the network layer. It may not detect it at the application layer, so CHAP method is recommended.Then the gateway challenges the client with XAUTH. CHAP preferred.
⌨️ 快捷键说明
复制代码Ctrl + C
搜索代码Ctrl + F
全屏模式F11
增大字号Ctrl + =
减小字号Ctrl + -
显示快捷键?