Set up VPN connections to support certificates

Important: VPN connections that support certificates are only established if the device has the correct time. Without the correct time, the device cannot correctly assess the validity of the certificates, which causes the certificates to be rejected: no connection will be established.

Several areas of the configuration have to be changed to set up VPN connections to support certificates.

The default IKE proposal lists and default IKE groups in LANconfig are located under VPN > IKE/IPSec > Default parameters:





Finally, the VPN connection parameters must be set up to use the correct IKE proposals ('IKE_RSA_SIG'). The values for 'PFS group' and 'IKE group' must agree with the values set in the IKE connection parameters.

The VPN connection parameters in LANconfig are located under VPN > IKE/IPSec > VPN connections > Connection parameters:





www.lancom-systems.com

LANCOM Systems GmbH | A Rohde & Schwarz Company | Adenauerstr. 20/B2 | 52146 Wuerselen | Germany | E‑Mail info@lancom.de

LANCOM Logo