SunScreen SKIP User's Guide, Release 1.5.1

Setting Up an Encrypted Connection From a Host to an Encrypting Gateway or SunScreen

The following figure depicts the configuration in which a host is communicating with an encrypting gateway.

Figure 5-3 Communicating with an Encrypting Gateway

Graphic

In this case, both the host and the encrypting gateway, whether it be a gateway or a SunScreen, must

A machine must also have a local identity. Hosts can have many identities, but you must choose one to use when communicating with the remote host. This local identity consists of the local key type and the local key name.

Both machines install or generate their keys and exchange namespace/key ID information. You should do this over the telephone or some other out of band media.

Type the encrypting gateway's information into the Add System box of skiptool. Then, set the Tunnel Address field of this box to be the IP address of the intermediate system. This action lets certificate discovery ask the correct host for its certificate.

For example: You are contacting a gateway that has three networks attached to it (networks 199.190.177, 199.190.176, and 199.190.176) and these networks are to remain hidden. It also has a local host attached to it. You should set up the ACL in the host as shown in the following table.

Table 5-1 The ACL for the Host

Host 

Algorithm 

Tunnel Address 

Remote Key 

199.190.177.* 

V2 DES/DES 

Gateway 

Gateway's 

199.190.176.* 

V2 DES/DES 

Gateway 

Gateway's 

199.190.176.* 

V2 DES/DES 

Gateway 

Gateway's 

Local host 

V2 DES/DES 

Gateway 

Gateway's 

Default 

V2 DES/DES 

Gateway 

Gateway's 

You can configure a default so that everything is sent to the gateway where it will be decrypted and sent to the proper recipient in the clear. The recipients of the packets will not be aware of any encryption. The gateway will handle all the encryption and decryption of packets from and to everything behind it.