USER MANUAL – Z-PASS1/Z-PASS2
44
PC LAN
192.168.1.0/24
SCADA LAN
192.168.2.0/24
Z-PASS2 LAN
192.168.10.0/24
Z-PASS2 LAN
192.168.20.0/24
Z-PASS1 LAN
192.168.30.0/24
The “VPN Box Manager” application guides you in the configuration task, checking that no subnet/IP
address conflict is present in the network.
If subnet/conflicts cannot be avoided, using a “Single LAN” VPN is still possible if local IP addresses are not
used; devices can be reached by means of their VPN IP addresses and machines beyond them can be
reached by configuring some “port forwarding” rules on the Device Router (see 18.8 paragraph).
13.2
“Point-to-Point” VPN
The above figure gives an example of a “Point-to-Point” VPN.
In this scenario a PC (acting as a VPN Client) can connect, on demand, to only one Z-PASS and its subnet,
using local IP addresses. Since the client “sees” just one Z-PASS (and attached devices) at time, the same
subnet configuration can be assigned to different sites, without creating conflicts.
For this kind of VPN, the “VPN Box Manager” application lets define group of users that can connect only
to assigned devices.
The “VPN Client Communicator” application retrieves the list of devices which are available for the logged
user; then the user can select one device on the list and connect to it.