D-Link DFL-260E User Manual page 468

Network security firewall netdefendos version 2.40.00
Hide thumbs Also See for DFL-260E:
Table of Contents

Advertisement

9.6.2. Configuring SSL VPN in
NetDefendOS
Ethernet interface but it could also be another logical interface. For example, a PPPoE interface
could be used.
Server IP
The IP address on the listening interface on which to listen for SSL VPN connection attempts by
clients. This will typically be a public IPv4 address which will be initially accessed using a web
browser across the public Internet.
The Server IP must be specified and will not default to the IP of the Outer Interface.
Server Port
The TCP/IP port number at the Server IP used in listening for SSL VPN connection attempts by
clients. The default value is 443 which is the standard port number for SSL.
Client IP Options
Dynamic Server Address
Instead of a fixed IP address for the SSL VPN Server IP being handed out to clients, this option
makes it possible to hand out a Fully Qualified Domain Name (FQDN) instead.
For example, the FQDN might be specified as server.some-domain.com. When a client connects
to the SSL VPN interface, this FQDN is handed out to the client which then resolves the FQDN
using DNS to a specific IP address. This allows the server address to change dynamically with
only the DNS entry being changed.
If this option is specified, the Server IP in General Options above is ignored.
IP Pool
As described above, client IP addresses for new SSL VPN connections are handed out from a
pool of private IPv4 addresses. This pool is specified by an IP address object defined in the
NetDefendOS address book. It is not the same as an IP Pool object used with IPsec.
The pool addresses do not need to be a continuous range but must belong to the same network.
The Inner IP listed above must also belong to this network but must not be one of the pool IPs.
Primary DNS
The primary DNS address handed out to a connecting client.
Secondary DNS
The secondary DNS address handed out to a connecting client.
Add Route Option
Proxy ARP
So that SSL VPN clients can be found by a network connected to another Ethernet interface,
client IP addresses need to be explicitly ARP published on that interface.
This Add Route option allows the interfaces for ARP publishing to be chosen. In most situations
Note
In the current NetDefendOS version, the outer interface cannot be a VLAN
interface.
468
Chapter 9. VPN

Advertisement

Table of Contents
loading

This manual is also suitable for:

Dfl-860eDfl-1660Dfl-2560Dfl-2560g

Table of Contents