Page 180 of 226
Version: 3.3.5
– DR05 – 23.03.2017
Authentication
19.3.3
OpenVPN offers three fundamentally different authentication methods.
None: no certificate or key is needed. Used primarily for testing the connection. The tunnel data is also NOT
encrypted.
Static key: a key as required by each peer is generated for the connection. Similar to the password.
Certificates, X.509: the following three certificate variants are distinguished:
o
Each subscriber needs the same root CA and a personal certificate signed by the root CA.
o
Like 1, but with additional username/password verification.
o
Like 2, but without a personal certificate. In other words, subscribers only need a root CA and
username/password.
No authentication
19.3.4
This setting should primarily be used for test purposes. It provides a quick and easy way of testing the con-
nection with a peer (e.g. whether the correct ports are enabled). The data is sent UNENCRYPTED in this mode.
Authentication with static key
19.3.5
With symmetric encryption, authentication and encryption/decryption of the data is performed using one and
the same key (static key). The advantage of symmetric encryption is its speed: encryption and decryption take
much less time than with asymmetric encryption since the symmetric key is secure from a size of 90 bits.
The asymmetric key, on the other hand, must be at least 1024 bits. The disadvantage of symmetric encryp-
tion is that stations need to exchange keys. Each subscriber must obtain the key in a secure manner. A previ-
ously imported or generated key can be selected in the screen shown above.
Содержание mbNET MDH 810
Страница 12: ...Page 12 of 226 Version 3 3 5 DR05 23 03 2017 4 Technical Data...
Страница 135: ...Page 135 of 226 Version 3 3 5 DR05 23 03 2017 RS232 485 serial interfaces 17 2...
Страница 144: ...Page 144 of 226 Version 3 3 5 DR05 23 03 2017 Add PC PG station 17 4 5 Now you need to add a PC PG station...
Страница 201: ...Page 201 of 226 Version 3 3 5 DR05 23 03 2017 NAT 22 3 1 2...
Страница 202: ...Page 202 of 226 Version 3 3 5 DR05 23 03 2017 Status Modem 22 4 Note Not available at mbNET variants with WLAN...
Страница 214: ...Page 214 of 226 Version 3 3 5 DR05 23 03 2017 23 Extras LUA 23 1 You can activate LUA to write and execute LUA scripts...