C-M-G
Series
Manual
© TDT GmbH
Chapter 5: Network Configuration
Seite 85 von 136
Command
Description
Copy new identify.pub to au-
thorized_keys
The SSH key will be stored in the home directory of the user
under .ssh/authorized_keys
Use password as key
passphrase.
The user password will be used as key
5.17 SSL Tunnels
This menue provides the ability to configure the Stunnel service and add new stunnel connections.
Stunnel works as a universal SSL encrypted tunnel between client and router. Thereby it is possible to
encrypt any TCP connection in a very easy way.
Command
Description
Service name
Defines the name of the tunnel connection
TCP port
Defines the port from which ssl connections are accepted
Active?
Activate or deactivate the stunnel connection
Run inetd style program
In case the tunnel connection is used to start an inetd application
define the complete path to the application here. To add additional
startup parameters use the
with arguments
field.
Run program in PTY
In case the tunnel connection is used to start an application in a
terminal session define the complete path to the application here.
To add additional startup parameters use the
with arguments
field.
Connect to remote host
In case the tunnel connection should connect to a server define
the
remote hostname
and
remote port
here.
SSL certificate and key file
Choose „Use Webmin’s cert“ to use the Webmin SSL certificate.
For a custom certificate choose „Use cert in file“ and define the
complete path to the certificate.
Note
To upload your custom certificate onto the router use
a
Use
/etc/stunnel
.to store the certificate on the
router
TCP-wrappers name
With this option set to „Automatic“ the wrapper name is choosen
automatically. Otherwise define it manually.
Tunnel mode
Accept SSL and
connect normally
Router is working in server mode and
accepts incoming connections which were
then forwarded normally (unencrypted).
Accept normal and
connect with SSL
Router acts in client mode and accepts
„normal“ unencrypted connections which
were then forwarded to a server ssl
encrypted.
Outgoing source address
Enter outgoing source ip address here or leave this field empty to
let the router fill in the matching ip address automatically