
VPNConnection
toNokiaCryptoCluster500
VPNGateway
11 December 2002
This document explains how to configure a virtual private network
connection overanopennetworkfromaremotehostrunningSSH
Sentinel to a private network protected by a Nokia CryptoCluster
500 VPN gateway.

2
c
2000-2002 SSH CommunicationsSecurityCorp
No part of this publication may be reproduced, published, stored in an
electronic database, or transmitted, in any form or by any means, electronic, mechanical, recording,or otherwise, for any purpose, without the
prior written permission of SSH Communications Security Corp.
This software is protected by international copyright laws. All rights reserved. ssh
R
is a registered trademark of SSH CommunicationsSecurity
Corp in the United States and in certain other jurisdictions. SSH2,
the SSH logo, IPSEC Express, SSH Certifier, SSH Sentinel, SSH NAT
Traversal, IPSEC on silicon, Hypermode, SSH Accession, SSH Token
Master,SSH Secure Shell and Making the InternetSecure are trademarks
of SSH Communications Security Corp and may be registered in certain
jurisdictions. All other names and marks are property of their respective
owners.
THERE IS NO WARRANTY OF ANY KIND FOR THE ACCURACY OR USEFULNESS OF THIS INFORMATION EXCEPT AS
REQUIRED BY APPLICABLE LAW OR EXPRESSLY AGREED IN
WRITING.
SSH Communications Security Corp.
Fredrikinkatu 42
FIN-00100 Helsinki
FINLAND
SSH Communications Security Inc.
1076 East MeadowCircle
Palo Alto, CA 94303
USA
SSH Communications Security K.K.
House Hamamatsu-cho Bldg. 5F
2-7-1 Hamamatsu-cho, Minato-ku
Tokyo 105-0013, JAPAN
http://www.ssh.com/
e-mail: ipsec-sales@ssh.com (sales), sentinel-support@ssh.com (technical support)
Tel: +358 20 500 7030 (Finland), +1 650 251 2700 (USA), +81 3 3459 6830 (Japan)
Fax: +358 20 500 7031 (Finland), +1 650 251 2701 (USA), +81 3 3459 6825 (Japan)
c
2002 SSH Communications Security Corp. VPN with SSH Sentinel and Nokia CryptoCluster

CONTENTS 3
Contents
1 VPN Connection to Nokia CryptoCluster 500 VPN Gateway 5
1.1 Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5
1.1.1 Further Information . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5
1.1.2 Platform Requirements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5
1.2 Configuring Nokia CryptoCluster 500 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6
1.2.1 Prerequisites . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6
1.2.2 Enabling Client Access in CryptoCluster . . . . . . . . . . . . . . . . . . . . . . . 6
1.3 Configuring SSH Sentinel . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9
1.3.1 Prerequisites . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9
1.3.2 Creating the VPN Rule . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9
1.4 Troubleshooting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11
VPN with SSH Sentinel and Nokia CryptoCluster
c
2002 SSH Communications Security Corp.

4 CONTENTS
c
2002 SSH Communications Security Corp. VPN with SSH Sentinel and Nokia CryptoCluster