SETUP
DOC_DEV_Router setup guide_A
page 33
7
OpenVPN type VPN connection
7.1
Overview
An OpenVPN VPN tunnel allows to connect two networks in a safe and transparent way : Each device of the
first network can exchange data with any device of the other network.
10 OpenVPN connections can be set by one IPL or RAS router.
100 OpenVPN connections can be set by one SIG router.
500 OpenVPN connections can be set by one SIG VM router.
•
Glossary
The router which initiates the OpenVPN VPN is called the VPN client the other one is called the VPN server.
The router which initiates the connection is
called the VPN client
The connection is an outgoing connection
The router which receives the connection is
called the VPN server
The connection is an ingoing connection
•
Login and password authentication
Each OpenVPN connection can be authenticated using the Login & password of the VPN client.
•
Certificate authentication
The authentication of the two participants to the VPN connection can also be carried-out using certificates in
addition to a Login and password.
Coming from factory , a certificate produced by ETIC TELECOM is registered in the ETIC Router.
Other kinds of X509 certificates can be added. (see the Set-up>Security>X509 certificate).
The certificate used by each participant to the VPN must be delivered by the same authority.
•
NAT translation insensitivity
While IPSEC is sensitive to address translation of the source IP address by intermediate routers, OpenVPN is
not.
The reasons is the source IP address is not checked by OpenVPN to authenticate the remote router; Open
VPN authenticates the remote router with a Login password and certificate.
That characteristic makes OpenVPN very easy to implement in many situations and in particular when a
cellular router is used.
•
Implementation easiness
The transport level of OpenVPN is TCP or UDP; the port number can be selected
That characteristic makes OpenVPN very easy and reliable to implement in many situations and in particular
when a cellular router is used.
Содержание RAS Series
Страница 1: ...DOC_DEV_Router setup guide_A RAS IPL SIG _________________ SETUP GUIDE _________________ ...
Страница 8: ......
Страница 14: ......