beautypg.com

Section 35.3.13, Section 35.3.14, Section 35.3.15 – Westermo RedFox Series User Manual

Page 827

background image

Westermo OS Management Guide

Version 4.17.0-0

35.3.13

Select Remote Certificate

Syntax [no] remote-cert

Context

IPsec Configuration

context (Only valid when ”method cert” is set.)

Usage Select remote certificate, if the certificate of the trusted peer has been

imported to this WeOS unit.

The ”LABEL” is the reference of the certificate when imported to the WeOS
unit.

Use ”no remote-cert” to remove the selection of remote certificate.

Use ”show remote-cert” to show the remote certificate setting.

Default values Disabled

35.3.14

Manage Remote CA restrictions

Syntax [no] remote-ca >

Context

IPsec Configuration

context (Only valid when ”method cert” and ”no

remote-cert” are set.)

Usage Define restrictions of the peer’s CA. By default, the peer is required use

a certificate issued by the same CA as this unit (”same”).

Use ”remote-ca any” to allow peers with a certificate issued by any of the
CAs trusted by this unit. It is also possible to only accept peers with certifi-
cates issued by a specific CA (among the ones trusted by this unit) by the
”remote-ca dn setting.

”no remote-ca” will return to the default setting (”remote-ca same”).

Use ”show remote-ca” to show the remote CA setting.

Default values Same (”remote-ca same”)

35.3.15

Specify IP Address/domain name of remote unit

Syntax [no] peer

Context

IPsec Configuration

context

➞ 2015 Westermo Teleindustri AB

827

This manual is related to the following products: