Functions
MoRoS ADSL 2.1 PRO
In the sample configuration, the end points of the OpenVPN connection will have
the IP addresses 10.1.0.1 and 10.1.0.2. The VPN tunnel will be established within
an already existing WAN connection. The OpenVPN clients and servers must also
know which network is located behind the according tunnel ends. In the sample
configuration, this is the network 192.168.200.0/24 on one side. On the other side,
this is the network 192.168.1.0/24. As soon as the tunnel is established, data for
these target networks is sent through the OpenVPN tunnel. If only data with a
target in the network behind the tunnel end are to be transmitted via the WAN
interface, it is recommended to enable the firewall after successful configuration.
This will limit the communication to the port at which the OpenVPN tunnel is
established (default setting: UDP port 1194).
The MoRoS ADSL 2.1 PRO supports several authentication methods when
establishing the VPN tunnel:
Authentication type Usage
Characteristics
None
For testing purposes
and to connect
networks without
encryption.
No encrypted connection. It is
not possible to log in several
clients at the server at the same
time.
Static key
For encrypted
connections of one
client and one server
each in small
applications
Encrypted connection. It is not
possible to log in several clients
at the server at the same time.
User
name/password and
common CA
certificate (can only
be configured at the
OpenVPN client)
For encrypted
connections from one or
more clients to an
OpenVPN server.
Flexible application for several
clients. Cannot be used with the
MoRoS ADSL 2.1 PRO as
OpenVPN server.
Certificate-based;
each participant has
an individual
certificate and key.
For encrypted
connections from one or
more clients to an
OpenVPN server.
Solution for maximum security,
but the configuration is more
complicated. This is the
recommended operating mode.
Table 13: Authentication methods for OpenVPN
For detailed information and troubleshooting, we also recommend the OpenVPN
web site: http://openvpn.net/howto.html
58