XHub VPN Services Configuration - Mac OS X - IPSecuritas
AHDS VPN services are based on IPSec protocol tunnels.
Mac OS X based customers can use IPSecuritas
from Lobotomo Software to manage/create tunnels into the AHDS XHub network.
IPSecuritas is free, but please do consider making a donation by clicking on the Donate button on their website.
Follow these instructions to install and setup the IPSecuritas software.
You will need the VPN Connection Parameters checklist sent to you by AHDS support to fill in certain fields of the configuration.
- Download the IPSecuritas software and run the Installer package.
-
Create a New Profile named AHDS-XHub
Connections menu -> Edit Profiles...
-
On the General tab and enter the following settings:
- Remote IPSec Device: Enter VPN Parameter: Remote Device ex: d1.xhub.ahds.com
- Local Side: leave at "Host", leave IP Address blank
- Remote Side: select "Network" from the popup menu
- Network Address: Enter VPN Parameter: Network Address ex: 10.98.32.0
- Network Mask: Enter VPN Parameter: Network Mask ex: 20
-
Click on the Phase 1 tab and enter the following settings:
- Lifetime: 28800 seconds
- DH Group: 1024 (2)
- Encryption: AES 256
- Authentication: SHA-1
- Exchange Mode: Agressive
- Proposal Check: Obey
- Nonce Size: 16
-
Click on the Phase 2 tab and enter the following settings:
- Lifetime: 3600 seconds
- PFS Group: 1536 (5)
- Encryption: Uncheck all but AES 256
- Authentication: Uncheck all but HMAC SHA-1
-
Click on the ID tab and enter the following settings:
- Local Identifier: Select "User FQDN" and enter VPN Parameter: Tunnel ID into the field that appears: ex: dvpn1@xhub.ahds.com
- Remote Identifier: Address
- Authentication Method: XAuth PSK
- Preshared Key: Enter VPN Parameter: Preshared Key
- Username: Enter VPN Parameter: Username
- Store Password: If you click the checkbox another field will appear that you can use to store: VPN Parameter: Password, however we suggest you do not store your password for security reasons; you will need to enter it when you connect.
-
Leave the DNS tab blank:
-
Click on the Options tab and leave everything at the defaults except:
- Enable MODE_CFG: Checkbox on
- Local IP in Remote Network: Checkbox on
- NAT-T: Select "Enable" from the popup menu
-
The VPN configuration is now complete. Close the Connections window and click the Start button on the IPSecuritas window.
When the tunnel connection starts up and completes, you can now make connections to your endpoints for DDE 3270 or Claims FTP.
