P a g e
|
87
GWN7000 User Manual
Version 1.0.6.28
Encryption Algorithm
Choose the encryption algorithm from the drop-down list, in order to
encrypt data so that the receiver can decrypt it using same algorithm.
Digest Algorithm
Choose the digest algorithm from the drop-down list, which will
uniquely identify the data to provide data integrity and ensure that
the receiver has an unmodified data from the one sent by the original
host.
TLS Authentication
This option uses a static Pre-Shared Key (PSK) that must be
generated in advance and shared among all peers. This feature
adds extra protection to the TLS channel by requiring that incoming
packets have a valid signature generated using the PSK key.
TLS Pre-Shared Key
Enter the generated TLS Pre-Shared Key when using TLS
Authentication.
Allow Duplicate Client
Certificate
This option when enabled, allows multiple clients to connect with the
same certificate but cannot be used for site-to-site VPN.
Certificate Authority
Select a generated CA from the drop-down list.
Server Certificate
Select a generated Server Certificate from the drop-down list.
IPv4 Tunnel Network
Enter the network range that the GWN7000 will be serving from to
the OpenVPN® client.
Note:
The network format should be the following
10.0.10.0/16
.
The mask should be at least 16 bits.
Redirect Gateway
When redirect-gateway is used, OpenVPN® clients will route DNS
queries through the VPN, and the VPN server will need to handle
them.
Automatic Firewall Rule
Enable automatic firewall rule.
Push Routes
Specify route(s) to be pushed to all clients. Example: 10.0.0.1/8
LZO Compression
Select whether to activate LZO compression or no, if set to
“Adaptive”, the server will make the decision whether this option will
be enabled or no.
Allow Peer to Change IP
Allow remote change the IP and/or Port, often applicable to the
situation when the remote IP address changes frequently.
2.
Click
after completing all the fields.
3.
Click
on top of the WebGUI in order to apply changes.