Vpn; Openvpn (Site To Site ) - Teltonika RUT104 User Manual

3g
Hide thumbs Also See for RUT104:
Table of Contents

Advertisement

4.7 VPN

4.7.1

OpenVPN (site to site )

OpenVPN site to site graphical user interface (GUI) implementation allows connecting two
remote networks via point-to-point encrypted tunnel. OpenVPN implementation offers a cost-effective
simply configurable alternative to other VPN technologies. The OpenVPN security model is based on
SSL, the industry standard for secure communications via the internet. OpenVPN implementation uses
OSI layer 2 secure network extension using the SSL/TLS protocol. The typical VPN site to site
implementation using OpenVPN is presented in Figure 16.
Remote Endpoint IP
xxx.xxx.xxx.xxx
Server
Network IP
192.168.0.0/24
192.168.0.2
Local tunnel IP
Remote tunnel IP
Remote network IP
Remote network
subnet mask
The OpenVPN implementation requires server to have public IP or hostname. Also the remote
network subnets must be different as in Fig. 23 192.168.0.0/24 and 192.168.1.0/24. If the subnet will
be the same tunnel will not be created or may not function correctly due to routing rules.
The server and client have almost the same configuration. The difference in the client
configuration is the remote endpoint IP or hostname field. Also the client can set up the keep alive
settings. For successful tunnel creation a static key must be generated on one side and the same key
must be uploaded on the opposite side.
Role – Select "Client" or "Server" role for the device.
New configuration name – Set the name for OpenVPN configuration.
Edit – Press Edit button to edit the OpenVPN configuration.
Delete – Press Delete button to delete the OpenVPN configuration.
Internet
Tunnel IP 10.0.0.1
OpenVPN tunnel
Figure 16. Typical site to site OpenVPN tunnel configuration
Server configuration
10.0.0.1
10.0.0.2
192.168.1.0
255.255.255.0
Figure 17. OpenVPN instances
Tunnel IP 10.0.0.2
LAN2 192.168.1.2
Client configuration
Remote Endpoint IP
xxx.xxx.xxx.xxx
Local tunnel IP
10.0.0.2
Remote tunnel IP
10.0.0.1
Remote network IP
192.168.0.0
Remote network
255.255.255.0
subnet mask
Client
Network IP
192.168.1.0/24
20 |
P a g e

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents