C-M-G
Series
Manual
© TDT GmbH
Chapter 5: Network Configuration
Seite 66 von 136
Command
Description
Encrypt packets with cipher
algorithm
Name of the connection
Listen on IP
All:
accepts connections on all network addresses
String:
accepts connections only on given network addresses
Authenticate packets with
HMAC
The authentication of packets the packets occours with the given
HASH algorithm
Keepalive
Ping:
ping remote over the TCP/UDP control channel if no
packets have been sent for at least
n
seconds.
Ping-Restart:
restarts connection after
n
seconds pass without
reception of a ping or other packet from remote. (SIGUSR1
Signal)
(Default: 120; Disable: 0)
Max. new connections
Limit server to a maximum of
n
clients to connect in
m
seconds
(Servers only)
Allow clients with same
common name
Yes:
clients are allowed to use the same name
No:
clients have to use different names; if a client connects with
an existing name, the „older“ clients connection will be rejected.
(Servers only)
Route client-to-client traffic
Yes:
clients are allowed to exchange data to each other
No:
clients are not allowed to exchange data to each other
(Servers only)
Limit concurrent clients
Max. number of simultanously active connections to the
OpenVPN server (Servers only)
Allow remote to change IP
and/or port
Allows the client to use an own IP address and an own port
respectively to change servers preset
Enable Management
Yes:
starts an TCP server on the given port for management. For
security reasons it is recommended to set the IP address to
127.0.0.1 (localhost)
(Servers only)
Client’s remote host(s)
Defines the peers (Clients only)
Priority:
priority of the server
IP address:
servers IP address
Port:
OpenVPN Server port
Accept only host with X509
or common name
Accept only host with X.509 or common name (Clients only)
TLS Cipher Algorithm
Packets are encrypted with the given algorithm
TLS Retransmit Timeout
(sec)
If a control packet is sent to the OpenVPN client, it has to be
answered by the client within
n
seconds
(Default: 2)
Renegotiate Data Channel
Key (sec)
The data channel key is anew negotiated every
n
seconds
Use PKCS12 File
Uses a PKCS12 certificate
Certification Authority
Defines the Certification Authority (CA)
Certificate
.pem Certificate
Key
The clients private certificate
Diffie-Hellman Random File
File in .pem format, which contains the Diffie-Hellman parameter
Certificate Revocation File
Defines the Certificate Revocation File to verify the clients
certificate