EasyManuals Logo

NETGEAR FVS318G User Manual

NETGEAR FVS318G
422 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #308 background imageLoading...
Page #308 background image
Manage Users, Authentication, and VPN Certificates
308
NETGEAR ProSAFE VPN Firewall FVS318G v2
Your changes are saved.
Manage Digital Certificates for VPN Connections
The VPN firewall uses digital certificates (also known as X509 certificates) during the Internet
Key Exchange (IKE) authentication phase to authenticate connecting IPSec VPN gateways
or clients, or to be authenticated by remote entities. You can do the following:
On the VPN firewall, you can enter a digital certificate on the IKE Policies screen, on
which the certifica
te is referred to as an RSA signature.
On the VPN client, you can enter a digital certificate on the Au
thentication pane in the
Configuration Panel screen.
Digital certificates either can be self-signed or can be issued
by
certification authorities (CAs)
such as an internal Windows server or an external organization such as Verisign or Thawte.
However, if the digital certificate contains the extKeyUsage exten
s
ion, the certificate must be
used for one of the purposes defined by the extension. For example, if the digital certificate
contains the extKeyUsage extension that is defined for SNMPv2, the same certificate cannot
be used for secure web management. The extKeyUsage would govern the certificate
acceptance criteria on the VPN firewall when the same digital certificate is being used for
secure web management.
On the VPN firewall, the uploaded digital certificate is checked
for valid
ity and purpose. The
digital certificate is accepted when it passes the validity test and the purpose matches its use.
The check for the purpose must correspond to its use for IPSec VPN. If the defined purpose
is for IPSec VPN, the digital certificate is uploaded to both the IPSec VPN certificate
repository. However, if the defined purpose is for IPSec VPN only, the certificate is uploaded
only to the IPSec VPN certificate repository.
The VPN firewall uses digital certificates to authenticate connecting
VPN
gateways or clients,
and to be authenticated by remote entities. A digital certificate that authenticates a server, for
example, is a file that contains the following elements:
A public encryption ke
y to be used by clients for encrypting messages to the server.
Information identifying
the operator of the server.
A digital signature confirming the identity of the operator of the serve
r. Ideally, the
signature is from a trusted third party whose identity can be verified.
You can obtain a digital certificate from a well-known commercia
l
certification authority (CA)
such as Verisign or Thawte, or you can generate and sign your own digital certificate.
Because a commercial CA takes steps to verify the identity of an applicant, a digital certificate
from a commercial CA provides a strong assurance of the server’s identity. A self-signed
digital certificate triggers a warning from most browsers because it provides no protection
against identity theft of the server.
The VPN firewall contains a self-signed
digital certificate from NETGEAR. This certificate can
be downloaded from the VPN firewall login screen for browser import. However, NETGEAR

Table of Contents

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the NETGEAR FVS318G and is the answer not in the manual?

NETGEAR FVS318G Specifications

General IconGeneral
Power requirements12V DC, 1.5A
Firewall throughput250 Mbit/s
Maximum data transfer rate1000 Mbit/s
HTTP performance6000 transactions/sec
Wi-FiNo
DHCP serverYes
Number of VLANs256
VPN tunnels quantity12
WAN connectionEthernet (RJ-45)
Connectivity technologyWired
Ethernet LAN (RJ-45) ports9
Ethernet DMZ ports quantity1
Routing protocolsRIP-1, RIP-2
Supported network protocolsTCP/IP, UDP, ICMP, PPPoE
VPN supportIPsec (ESP), IKE, PKI, HTTPS
Security algorithms128-bit AES, 192-bit AES, 256-bit AES, 3DES, DES, MD5, SHA-1
Internal memory128 MB
Flash memory32 MB
Storage media typeFlash
Processor frequency300 MHz
Storage temperature (T-T)-20 - 70 °C
Operating temperature (T-T)0 - 45 °C
Cables includedLAN (RJ-45)
Weight and Dimensions IconWeight and Dimensions
Weight590 g
Dimensions (WxDxH)190 x 125 x 35 mm

Related product manuals