2.
VPN
Client
(Air
Side)
A.
Install
OpenWRT
on
the
router
Follow the same directions as for the server to install OpenWRT.
B.
Configure
the
router
(1) Set the router LAN IP to 192.168.1.2. Disable the DHCP server.
(2) Delete WAN6 interface from Network -> Interfaces.
(3) Temporarily connect the router to the internet (via WAN port or use a mobile hotspot on the
mobile phone) and open an SSH session.
(4) Execute the following commands to install required packages:
# opkg update
# opkg install openvpn-openssl luci-app-openvpn
(5) Using the LUCI WebUI Select VPN -> OpenVPN. Then enter smallsatcom_tap in the instance
name below “Template Based Configuration” Select “Client configuratio
n f
or an ethernet
bridge VPN” from the template list and click Add. Click Edit next to the newly added interface.
(6) (Some field
s m
ight be missing; these can be added by going to the bottom of the page and
selecting it from the “Additional-field
" d
rop-down menu.) Enter the following configuration
• verb: 3
• port: 1194
• dev_type: tap
• nobind: [tick]
• comp_lzo: yes
• client: [tick]
• remote: [Public ip address or ddns address of the VPN Server]
• ca: [click to upload and select ca.crt downloaded from server]
• dh: [do not select any file
• cert: [click to upload and select smallsatcom.crt downloaded from server]
• key: [click to upload and select smallsatcom.key downloaded from server]
• proto: udp
(7) Click Save & Apply, then Back to Overview.
(8) Tick the “Enabled” box next to the “smallsatcom_tap” line. Save & Apply and then Start the
VPN Server.
(9) Open LAN interface settings, go to “Physical Settings” tab and add “tap0” to the interfaces from
drop-down list. Save, then Save & Apply.
(10) Reboot the router to Apply all changes.
(11) If the server is running, the client should now establish a VPN connection. This can be
confirme
d b
y inspecting the System Log and the VPN Server router should reply to ping.
(12) Disconnect the temporary internet connection and select edit next to the WAN interface
under Network -> Interfaces. Change Protocol to PPPoE. Enter “void” in both username and
passwords fields Enter “@Background” to Service Name field
. S
ave, then Save & Apply.
Page 4
8
1
8
Feb 2021
© Honeywell International Inc. Do not copy without express permission of Honeywell.
SYSTEM DESCRIPTION, INSTALLATION, AND MAINTENANCE MANUAL
SMALL SATCOM