Virtual Private Networks (VPN)
OpenVPN
IX14 User Guide
587
Command line
1. Log into the IX14 command line as a user with full Admin access rights.
Depending on your device configuration, you may be presented with an
Access selection
menu
. Type
admin
to access the Admin CLI.
2. At the command line, type
config
to enter configuration mode:
> config
(config)>
3. At the config prompt, type:
(config)> add vpn openvpn server
name
(config vpn openvpn server
name
)>
where
name
is the name of the OpenVPN server.
The OpenVPN server is enabled by default. To disable the server, type:
(config vpn openvpn server
name
)> enable false
(config vpn openvpn server
name
)>
4. Set the mode used by the OpenVPN server:
(config vpn openvpn server
name
)> device_type
value
(config vpn openvpn server
name
)>
where
value
is one of:
n
TUN (OpenVPN managed)
—Also known as routing mode. Each OpenVPN client is
assigned a different IP subnet from the OpenVPN server and other OpenVPN clients.
OpenVPN clients use Network Address Translation (NAT) to route traffic from devices
connected on its LAN interfaces to the OpenVPN server.
n
TAP - OpenVPN managed
—Also know as bridging mode. A more advanced
implementation of OpenVPN. The IX14 device creates an OpenVPN interface and uses
standard interface configuration (for example, a standard DHCP server configuration).
n
TAP - Device only
—An alternate form of OpenVPN bridging mode, in which the device,
rather than OpenVPN, controls the interface configuration. If this method is is, the
OpenVPN server must be included as a device in either an interface or a bridge.
See
for information about OpenVPN modes. The default is
tun
.
5. If
tap
or
tun
are set for
device_type
:
a. Set the IP address and subnet mask of the OpenVPN server.
(config vpn openvpn server
name
)> address
ip_address/netmask
(config vpn openvpn server
name
)>