For client: Certificate Authority (CA), Client certificate, Client key.
For server: Certificate Authority (CA), Server certificate, Server key and Diffie-Hellman (DH)
certificate used to key exchange through unsafe data networks.
All mention certificates can be generated using OpenVPN or OpenSSL utilities on any type
host machine. Certificate generation and theory is out of scope of this user manual.
8.
Remote host IP
address
IP address of OpenVPN server (applicable only for client configuration).
9.
Resolve Retry
Sets time in seconds to try resolving server hostname periodically in case of first resolve
failure before generating service exception.
10. Keep alive
Defines two time intervals: one is used to periodically send ICMP request to OpenVPN server,
and another one defines a time window, which is used to restart OpenVPN service, if no ICPM
request is received during the window time slice. Example Keep Alive “10 60”
11. Remote network
IP address
IP address of remote network, an actual LAN network behind another VPN endpoint.
12. Remote network
IP netmask
Subnet mask of remote network, an actual LAN network behind another VPN endpoint.
13. Certificate
authority
Certificate authority is an entity that issues digital certificates. A digital certificate certifies the
ownership of a public key by the named subject of the certificate.
14. Client certificate Client certificate is a type of digital certificate that is used by client systems to make
authenticated requests to a remote server. Client certificates play a key role in many mutual
authentication designs, providing strong assurances of a requester's identity.
15. Client key
Authenticating the client to the server and establishing precisely who they are
After setting any of these parameters press
“Save”
button. Some of selected parameters will be shown in the
configuration list table. You should also be aware of the fact that router will launch separate OpenVPN service for every
configuration entry (if it is defined as active, of course) so the router has ability to act as server and client at the same
time.
7.5.2
IPSec
The IPsec protocol client enables the router to establish a secure connection to an IPsec peer via the Internet.
IPsec is supported in two modes - transport and tunnel. Transport mode creates secure point to point channel between
two hosts. Tunnel mode can be used to build a secure connection between two remote LANs serving as a VPN solution.
IPsec system maintains two databases: Security Policy Database (SPD) which defines whether to apply IPsec to a
packet or not and specify which/how IPsec-SA is applied and Security Association Database (SAD), which contain Key of
each IPsec-SA.
The establishment of the Security Association (IPsec-SA) between two peers is needed for IPsec communication. It
can be done by using manual or automated configuration.
Note: router starts establishing tunnel when data from router to remote site over tunnel is sent. For automatic
tunnel establishment used tunnel Keep Alive feature.
86
Содержание RUT900
Страница 1: ...1 USER MANUAL RUT900 3G Router ...
Страница 7: ...10 3 Bootloader s WebUI 139 11 Glossary 140 7 ...
Страница 9: ...Device connection 9 ...
Страница 11: ... Storage humidity 5 to 95 Non condensing 1 5 Applications 11 ...
Страница 28: ...5 3 1 10 Topology Network scanner allowing you to quickly retrieve information about network devices 28 ...
Страница 84: ...There can be multiple server client instances 84 ...
Страница 108: ...7 9 3 Scheduled Messages Scheduled messages allows to periodically send mobile messages to specified number 108 ...
Страница 120: ...7 11 4 2 Template In this page you can review landing page template HTML code and modify it 120 ...