Introduction

This chapter describes a certificate-based VPN IPSec connection of the bintec secure IPsec client™ to a bintec R3000™ VPN gateway. An owned certification authority (OpenSSL CA) is set up to generate the required certificates in PKCS#12 format. When the VPN tunnel is set up, a dynamic IP address is assigned to the bintec secure IPSec client™ (per IKE config mode). The solution can be optionally upgraded with one-time password request. Here, a one-time password in generated with a KOBIL SecOVID™ token authenticated on the KOBIL SecOVID™ server.

Example scenario

Requirements