TOPEX Bytton (HSPA+ / LTE)
ByttonLTE(full)_genericUsermanual_sw306FAS_revN.1.docx
Page: 162 / 290
5.4.4 OVPN
Here are the settings for the Open VPN tunnel of Bytton:
Figure 5-93: OVPN page for secure Tunnels.
Why Open VPN?
OVPN is a recent addition to the range of secure IP tunnels supported by Bytton for the purpose of
securely tunnel the data through a single TCP/UDP port over an unsecured network such as mobile
Internet and thus establish VPNs. OVPN is simple, easy to set up and use, and still powerful. GRE and
IPSec have been implemented previously, but now you can use OpenVPN too, on the Bytton LTE
equipments!
While other VPN solutions often use proprietary or non-standard mechanisms, OpenVPN has a modular
concept, both for underlying security and for networking.
OPN does not suffer from the complexity that characterizes other VPN implementations like the market
leader IPSec.
However, it is versatile and powerful - it provides features which that go beyond the scope of every other
VPN implementations.
For instance, OpenVPN offers two different basic modes, which run either as Layer 2 or Layer 3 VPN.
Thus, OpenVPN tunnels on Layer 2 can also transport Ethernet frames, IPX packets, and Windows
Network Browsing packets (NETBIOS), all of which are problems in most other VPN solutions. It extends
the protection of the central firewall in the company's main office to all users out in the field, which are
connected via OVPN tunnels.
OpenVPN connections can be tunneled through almost every firewall and proxy. The OVPN Server
running on Bytton LTE can be configured to run either as a TCP, or as UDP.
As can bee seen from the configuration page, just a single port in the firewall must be opened to allow
incoming connections. Its masquerading feature means there are no problems with NAT - Both OpenVPN
server and clients can be within a network using only private IP addresses. Every firewall can be used to
send the tunnel traffic to the other tunnel endpoint. It also provide Transparent, high-performance support
for dynamic IPs, Both tunnel endpoints can have low-cost broadband access with dynamic IPs. The
changes of IP on either side will be seldom seen by the users.