Lantronix X300 Series X300 Series User Guide Rev B - Page 80

OpenVPN, OpenVPN Instances

Page 80 highlights

9: VPN Parameters DH Group Description Select the desired Diffie-Hellman group to use:  Any  Group 1 (768)  Group 2 (1024)  Group 5 (1536)  Group 14 (2048)  Group 15 (3072)  Group 16 (4096)  Group 17 (6144)  Group 18 (8192) Higher-numbered groups are more secure but also require longer to generate the key. The default group is "Any". DPD Keep Alive Time Enter the time in seconds for interval between Dead Peer Detection keep alive messages. DPD Timeout Enter the time in seconds of no response from peer before Dead Peer Detection times out. IKE Re-key Time Enter the time in seconds between changes of the encryption key. To disable changing the key, set it to 0. SA Life Time Enter the time in seconds for the security association lifetime. DPD Action Select the desired Dead Peer Detection action. This action must be taken when a dead IKE peer is detected. 4. Click Save. The instance is saved and displayed on the IPsec page. 5. After configuring the profile, click Connect to start the IPsec connection for the first time. OpenVPN VPN > OpenVPN OpenVPN is an open-source software application that implements virtual private network (VPN) techniques for creating secure point-to-point or site-to-site connections. It uses the OpenSSL library to provide encryption of both the data and control channels. OpenVPN can run over UDP or TCP transports, multiplexing created SSL tunnels on a single TCP/UDP port. OpenVPN fully supports IPv6 as the protocol of the virtual network inside a tunnel and the OpenVPN applications can also establish connections via IPv6. It has the ability to work through most proxy servers (including HTTP) and is good at working through network address translation (NAT) and getting out through firewalls. The server configuration has the ability to push certain network configuration options to the clients, including IP addresses, routing commands, and a few connection options. The X300 series gateways support OpenVPN client, server, and pass through. OpenVPN Instances The OpenVPN client will attach itself to the configured OpenVPN server over any available WAN, LAN, or Cellular network interface. If the auto-connect function is enabled, OpenVPN will connect over available WAN, switch between WAN connections when one WAN fails-over to another, and also auto start on every reboot. X300 Series IoT Cellular Gateway User Guide 80

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216

9: VPN
X300 Series IoT Cellular Gateway User Guide
80
4.
Click
Save
. The instance is saved and displayed on the IPsec page.
5.
After configuring the profile, click
Connect
to start the IPsec connection for the first time.
OpenVPN
VPN > OpenVPN
OpenVPN is an open-source software application that implements virtual private network (VPN)
techniques for creating secure point-to-point or site-to-site connections. It uses the OpenSSL
library to provide encryption of both the data and control channels. OpenVPN can run over UDP or
TCP transports, multiplexing created SSL tunnels on a single TCP/UDP port.
OpenVPN fully supports IPv6 as the protocol of the virtual network inside a tunnel and the
OpenVPN applications can also establish connections via IPv6. It has the ability to work through
most proxy servers (including HTTP) and is good at working through network address translation
(NAT) and getting out through firewalls. The server configuration has the ability to push certain
network configuration options to the clients, including IP addresses, routing commands, and a few
connection options.
The X300 series gateways support OpenVPN client, server, and pass through.
OpenVPN Instances
The OpenVPN client will attach itself to the configured OpenVPN server over any available WAN,
LAN, or Cellular network interface. If the auto-connect function is enabled, OpenVPN will connect
over available WAN, switch between WAN connections when one WAN fails-over to another, and
also auto start on every reboot.
DH Group
Select the desired Diffie-Hellman group to use:
Any
Group 1 (768)
Group 2 (1024)
Group 5 (1536)
Group 14 (2048)
Group 15 (3072)
Group 16 (4096)
Group 17 (6144)
Group 18 (8192)
Higher-numbered groups are more secure but also require longer to
generate the key.
The default group is “Any”.
DPD Keep Alive Time
Enter the time in seconds for interval between Dead Peer Detection
keep alive messages.
DPD Timeout
Enter the time in seconds of no response from peer before Dead Peer
Detection times out.
IKE Re-key Time
Enter the time in seconds between changes of the encryption key. To
disable changing the key, set it to 0.
SA Life Time
Enter the time in seconds for the security association lifetime.
DPD Action
Select the desired Dead Peer Detection action. This action must be
taken when a dead IKE peer is detected.
Parameters
Description