Custom TLS/SSL Certificate. IAC-BOX IAC-BOX
Reklāma
Reklāma
IAC-BOX Documentation, Release 1.0
– The selected protocol will be blocked completely. This option is useful for example for P2P file sharing and other unallowed protocols.
• Drop
– This option will drop the packet without sending any reject related information to the counterside.
Please note that due to the encryption of many protocols, the selected action (log, shape, reject, drop) for the protocol will take effect only for new sessions. That means, that already opened connections may not be affected when activating the Application Control.
At the Live View you can see the traffic of all activated protocols.
This will give you an overview of the protocols used in the Surf-LAN and allows you to decide what protocols you want to allow, block or restrict.
4.3 Custom TLS/SSL Certificate
Hint:
• TLS (the successor of SSL) is the only secure protocol that is used, but in combination with certificates the term SSL is still used very often.
• Basic knowledge about TLS-certificates is required, this document expects a certain level of familiarity with TLS and X.509.
• The IAC-BOX does only support PEM certificates, DER certificates have to be converted.
• The key file must not be password protected.
• Intermediate certificates have to be appended to the ca-file.
• System Administrators are in charge to backup the key-files and store them securely.
4.3.1 Using a custom certificate
You can use any PEM type certificate on the IAC-BOX. To enable the option to upload your certificate navigate to Settings / Network / General and change the hostname and domainname according to your certificate.
4.3. Custom TLS/SSL Certificate 84
Lejupielādēt
Reklāma