Tutorial changes

Roger Hartmuller <[email protected]> Thu, 5 Jun 2003 10:06:48 -0400 (EDT)
Newsgroups gmane.network.net-policy.user
Message-ID <Pine.GSO.4.33.0306051004500.19031-200000@raven>
Attached are the changes needed that I have found:
tutorial-errors (text/plain, 2.3 KB)
Changes for the tutorial: (based on tutorial.html from the latest CVS)

1. Under Navigating the GUI, the last paragraph, the middle sentence
should read "You can see what policy conflicts have been created."

2. Under Defining some network policies, under 2. Create the policy.

The 1st step should be to select Manage Policies, and then Create New.

The next screen shows boxes to check or uncheck - this needs to be added.
I assume this would be Notification generator to check.

In Step 3.1., the button is called "Add a new notification log destination"

The next screen is "Select policies to apply data to" and needs to be
included here. (This section needs re-working.)

The next screen is Setting up a notification reciever.

The extra parameters and the community name are in the same screen.

In Step 4. 2., It is a pull-down list, not a box check.

The next screen is Modify clients or policies in role 'notification 
generator'. You need to check either 'modifiy clients' or 'modify policies'.

Explain how to finish here.

3. Filters and Actions: A more complex example

Step 1. 4. This screen is Modify clients or policies in role 'telnet 
server'. You have to check 'Modify clients'. The next screen then gives
the list of clients. (Aside: Should we create 2 clients here, as we did
in our testing previously?)

-----------------------------------------
At this point, I reset the database, to go thru as if we had NOT done the 
notification example.

Under Step 2. 6. - SA Direction is listed twice - Do you want 
SA DF handling:?

Step 3. 1. has you creating hosts again. That was already done
in Step 1.

Pick it up with 3. 2.

4. IKE and IPSEC: A more complex example

This states "This example assumes that the preconfigured action example 
has already been completed."

I think I remember that committing the preconfigured action prior to 
doing the IKE example caused a problem with the clients, so I always 
did the IKE example stand-alone.

This means I created the hosts first, an then did the firewall rule.

In Step 5., the responder negotiation parameters should read

min 1m; refresh 90%; can idle

In Step 8., the responder negotiation parameters should read

min 1m; refresh 90%; can idle

At the end, you have to create the ip filter.