Virtual Private Networks (VPN)
OpenVPN
LR54 User Guide
498
c. For
Zone
, select the appropriate firewall zone from the dropdown.
See
for information about firewall zones.
d. Click
again to allow access through additional firewall zones.
11. (Optional) Click to expand
Advanced Options
to manually set additional OpenVPN
parameters.
a. Click
Enable
to enable the use of additional OpenVPN parameters.
b. Click
Override
if the additional OpenVPN parameters should override default options.
c. For
OpenVPN parameters
, type the additional OpenVPN parameters.
12. Click
Apply
to save the configuration and apply the change.
Command line
1. Select the device in Remote Manager and click
Actions
>
Open Console
, or log into the LR54
local command line as a user with full Admin access rights.
Depending on your device configuration, you may be presented with an
Access selection
menu
. Type
admin
to access the Admin CLI.
2. At the command line, type
config
to enter configuration mode:
> config
(config)>
3. At the config prompt, type:
(config)> add vpn openvpn server
name
(config vpn openvpn server
name
)>
where
name
is the name of the OpenVPN server.
The OpenVPN server is enabled by default. To disable the server, type:
(config vpn openvpn server
name
)> enable false
(config vpn openvpn server
name
)>
4. Set the mode used by the OpenVPN server:
(config vpn openvpn server
name
)> device_type
value
(config vpn openvpn server
name
)>
where
value
is one of:
n
TUN (OpenVPN managed)
—Also known as routing mode. Each OpenVPN client is
assigned a different IP subnet from the OpenVPN server and other OpenVPN clients.
OpenVPN clients use Network Address Translation (NAT) to route traffic from devices
connected on its LAN interfaces to the OpenVPN server.
n
TAP - OpenVPN managed
—Also know as bridging mode. A more advanced
implementation of OpenVPN. The LR54 device creates an OpenVPN interface and uses
standard interface configuration (for example, a standard DHCP server configuration).
n
TAP - Device only
—An alternate form of OpenVPN bridging mode, in which the device,
rather than OpenVPN, controls the interface configuration. If this method is is, the
OpenVPN server must be included as a device in either an interface or a bridge.