OVERVIEW
Page 12
DOC_DEV_SIG_ User guide_A
4.2
Main functions
IPSec VPN and OpenVPN VPN for safety
VPN connection guarantees a high level of performance and security:
Transparency: The VPN interconnects the two networks so that any machine in one network can
communicate with a machine on the other network.
Authentication: The router that establishes the VPN is authenticated by the one that accepts it and any
other connection is rejected.
Confidentiality: Data traffic via the VPN is encrypted.
The SIG allows the simultaneous establishment of IPSec and OpenVPN tunnels (100 in total).
Although the SIG is designed to perform the VPNs concentrator function (also known as VPN server), it can
either behave as a server or as a VPN client.
The SIG provides 4 independant OpenVPN servers. Each of these OpenVPN servers can be set differently to
meet the technical requirements (key refresh period, type of encryption ...).
The IPSec setting can be different for each VPN.
These different characteristics make it possible to accept OpenVPNs or IPSec VPNs originating from routers
of different manufacturers and also to take into account backup paths in order to build high availability remote
control systems.
Remote access server for PCs, tablets and smartphones
The SIG can also behave like a remote access server.
If he is registered in the user list, a remote user can access to particular devices of a machine network
depending on his identity.
The new HTTPS portal make possible to access easily and safely to HMIs or PLCS web servers using a tablet,
a PC or a smartphone.
IP router
The SIG provides powerful, flexible and comprehensive solutions to route IP packets from one network to other
networks :
Static routes, to reach nested networks,
Network address t
ranslation d‘adresse (NAT, DNAT, port forwarding),
Routing protocol (RIP),
Domain name management DNS et DynDNS.
Firewall
The firewall protects against the sophisticated attacks coming from the Internet.
It is also able to filter IP frames between the WAN interface or any VPN interface on one hand, and the LAN
interface on the other hand.