
September 28, 2016
INFODRAW R&D PMRS/TMRS-201 User Manual v6.0.0.2
136
4-3-7 OpenVPN
:
The PMRS unit supports OpenVPN. OpenVPN is a robust and configurable VPN (Virtual
Private Network) daemon which can be used to securely link the PMRS and the MRS server
on private networks using an encrypted tunnel over the Internet.
The PMRS with firmware versions 5.0.0.8 and above includes a configurable OpenVPN client
version 2.3.2. This OpenVPN client is capable of connecting to an OpenVPN server using the
InfoBoxx built-in cellular modem connection. It connects using the default OpenVPN settings
of UDP port 1194 and creates a virtual network over this connection. This virtual network
can be encrypted using TLS if provided with the authentication parameters: RSA certificate,
key, and CA certificate. TLS supports a number of ciphers, including DES (40 bits), 3DES (168
bits), AES (256 bits) and RC4 (128 bits). The selected encryption cipher is a result of the
negotiation between the TLS client and the TLS server.
In order to have the PMRS media connection encrypted as part of the VPN, it must use the
virtual network addresses instead of the internet addresses in the MRS Connection section
of the Device Config Utility. Either the PMRS is a client that connects to an MRS Server using
its virtual address (in the remote address field), or it is a server (local server selection) and
the MRS Client will use the virtual address of the PMRS device to connect there. When using
the virtual network addresses, it is possible to have a PMRS working as a server with a
known virtual address even if it receives a dynamic or private address from the cellular
provider. Read the OpenVPN manual for more information about configuring OpenVPN on:
http://openvpn.net/index.php/open-source/documentation/howto.html