ICX35-HWC ♦ Industrial Cellular Gateway
ICX35-HWC Webpage
3G/4G LTE
User Manual
ProSoft Technology, Inc.
Page 33 of 127
Parameter
Description
Default Gateway
Interface to be used as a default gateway. By default, it is set to
Cellular
interface
. It can also be set to pass the traffic through one of the configured
tunnels -
OpenVPN Server 1
.
Select the OpenVPN
Server to be configured
The OpenVPN Server instance that is being configured.
TLS Renegotiation Time Transport layer Security renegotiation time in seconds. This controls how
often the underlying SSL/TLS session renegotiates. This provides additional
security by frequently rekeying the session keys. Default value: 3600.
Server Address
IP address or hostname of the VPN server. This is the IP Address that you
are creating the tunnel to. In the previous example, this is the public IP
Address of the ICX35-HWC in pass through mode that is being used as the
default connection to the Linux server.
Server Port
Service port number on the VPN server. The default port is
1194
. This is the
port number for the OpenVPN. Port 1194 is the default port designated for
OpenVPN. This is the port number used for the previous example.
Encryption Cypher
Cipher used to encrypt data channel packets. The default value is
BF-CBC
.
Some of the ciphers that are supported by OpenVPN are not available in this
list because they are considered insecure. However, these can still be used
by using a custom configuration file.
Static Routes
Static routes to remote networks to be specifically accessed through the
configured OpenVPN connection. A maximum of 3 static routes are supported
per tunnel.
Enable User / Password
Authentication
Alternative authentication method based on username and password. Enter a
Username
and
Password
.
Credential Files
Certificate Authority
- VPN authentication that issues certificates for VPN,
Secure Internal Communication (SIC), and users.
Client Certificate
- Issued by a certificate authority as proof of identity.
Client Key
- Password to the corresponding client certificate.
Click the
Choose File
button to locate these files. Internally, they are
renamed (Example: file_OpenVPN_CA.crt), and stored in the appropriate
Current File
area.
Note: These Credential files are mandatory in order to enable OpenVPN.
They can either be uploaded individually or have their content added inline,
within the custom configuration file. If by mistake you uploaded them and
also have them inline in the configuration file, the files uploaded individually
will take precedence.
Custom Config File
Click the
Choose File
button to locate and upload a custom OpenVPN
configuration file, which overrides any credential files previously loaded. If you
have not previously uploaded any credential files, the Custom Configuration
File should include them.
Protocol
The protocol to use when connecting with the remote:
TCP
or
UDP
(default).
The following table lists the OpenVPN default values:
Parameter
Default Value
Server/Client
Client
Interface
Tun
Protocol
UDP
Authorization
None
Encryption Cipher
Undefined (Should be defined by the server). Default:
BF-CBC
TLS Renegotiation Time
3600 seconds
LZO Compression
Adaptive
Port
User-configurable. Default:
1194
Server address
User-configurable