Configuring with Web Based Management
4.9 Security
SINEMA Remote Connect - Server
100
Operating Instructions, 11/2017, C79000-G8976-C383-04
Configuring OpenVPN
Configure the following settings that are valid for all OpenVPN connections after you have
saved:
Box
Meaning
Activate
When enabled, OpenVPN is used.
Status
Shows whether OpenVPN is enabled or disabled.
TCP port
Specify the port on which the SINEMA RC Server server accepts TCP connections. As-
suming that TCP frames can be sent to this port. In a preconnected DSL router, for exam-
ple, port forwarding must be entered.
UDP port
Specify the port on which the SINEMA RC Server server accepts UDP connections. As-
suming that UDP frames can be sent to this port. In a preconnected DSL router, for exam-
ple, port forwarding must be entered.
Keep alive interval (s)
Enter the interval in seconds at which connection partners send keep alive packets. This
setting is automatically transferred to the client when the connection is established.
The keep alive packets are sent only when there was no communication during the last
interval.
If there is no response to the packet, the communications partner assumes an interruption
on the connection or that the communications partner is not functioning. Measures are
taken according to the "Connection timeout" setting.
Connection timeout (s)
Specify the maximum time in seconds that the communications partner waits for a re-
sponse from the server before the connection is considered to be interrupted. This setting
is automatically transferred to the client when the connection is established.
Detection of a connection interruption is achieved with keep alive packets (see setting
"Keep alive interval").
If the client detects a connection interruption, it reacts by re-establishing the connection
when the connection timeout has elapsed.
On the server the set connection timeout is doubled. After the doubled connection timeout
has elapsed, the server considers the connection to the client as being interrupted.
DH key length
Select the Diffie-Hellman key exchange protocol to be used between the communications
partners.
Cipher
Selection of the algorithm for encryption of the transferred data. The following are available:
•
AES-128, 192, 256: Advanced Encryption Standard (128, 192 or 256 bit key length,
mode CBC)
•
DES-EDE, DES-EDE3: Data Encryption Standard (128 or 192 bit key length, mode
CBC)
Hash method
Selection of the authentication algorithm:
SHA-1, 256, 512: Secure Hash Algorithm 1, 256 or 512
Min. TLS version
Specify the TLS version.
Interface
The interface that forms the local VPN endpoint. Via this interface the OpenVPN connec-
tion to the OpenVPN partner (SINEMA RC client, device) is established.
•
WAN: Connection only via the WAN interface
•
LAN 1-n: Connection via available LAN interfaces:
•
WAN + LAN 1-n: Connection via all interfaces