WestermoConnect User Guide VPNeFree Service
Contents VPNeFree 3 User Portal 4 SSL VPN Client 6 Windows Vista & 7 Settings 7 Testing the Connection 8 Troubleshooting 9
VPNeFree Welcome to the VPNeFree WestermoConnect service. With this level of access you will be able to use a software VPN client to remotely access the network LAN of up to three Westermo routers. The VPN client can be installed on multiple machines, but only one instance can be connected at any one time. The client needs to be installed on a PC running Windows 2000/XP/Vista/7 with access to the Internet. VPN Client Internet Remote Networks Windows PC SSL VPN Tunnels Remote #1 Remote #2 WestermoConnect Remote #3 Your router(s) will be delivered with its configuration settings programmed and the IP address already assigned. The IP address will be unique to that router and must not be changed. Any connected devices must use an IP address within the same subnet. A letter detailing the IP address assignments for your devices and user credentials for the VPN client will accompany the equipment. Wireless Routers If you supplied the name of the mobile network you are planning to use then the Access Point Name (APN) will already have been configured for you. Otherwise this setting will need to be entered to enable the SIM card to function correctly. Refer to the product user guide for how to configure this for your particular router model. ADSL Routers You will need to have supplied the username and password for your ISP to allow the router to connect to the internet. Otherwise this setting will need to be entered to enable the router to function correctly. Refer to the product user guide for how to configure this for your particular router model. For routers configured to use Ethernet only connections, the router will be marked to indicate which ports are configured for connection to the local network and the corporate network. Page 3
User Portal To begin using the service you will need to download the VPN client software onto a PC. Using a web browser, with access to the internet, enter the following address: https://vpnefree.westermoconnect.net Ignore any warnings about security certificates not being trusted. This is an issue with the browser not recognising the certificate authority and does not represent a security risk. You should now be presented with the following login screen: You will need the username and password provided in your welcome letter to log onto the site. Once you have logged in, click on the Remote Access menu and you should have three download options displayed. Select the top option and download the ZIP file. This file contains the setup file which should be run to do a complete installation of the software. Follow the on screen instructions as directed. During the software installation you may get a warning indicating that the software has not passed Windows Logo testing. You can ignore this warning and click on the Continue Anyway button Page 4
For best security practice, we would recommend changing the password from the original. This is accessed via the User Portal by selecting the Change Password option on the menu bar. Changing this password will affect both the User Portal login and the VPN Client login, so please make a note of the new password. If you forget the new password you will need to contact Westermo to have it reset. Page 5
SSL VPN Client Once the Remote Access SSL VPN Client has been installed a traffic light icon will appear in the right hand corner of the taskbar, and should be showing a red light to indicate no current connection. The Remote Access SSL VPN Client will be identified in the Windows menus as Astaro SSL VPN Client The VPN Client task bar icon uses a traffic light sequence to show its current status. The three different statuses are as follows: Offline Connecting Connected To initiate a VPN connection double-click on the traffic light icon on the taskbar. Now enter the username and password provided, or the new password if you have changed it, and click on the OK button. The traffic light will change to red/amber then green when connected and a message indicating the assigned IP address will briefly appear To disconnect the VPN client connection, right click on the traffic light icon and select Disconnect If the PC is running Windows Vista or Windows 7, the User Account Control setting must be altered to allow the VPN client to run correctly. (Refer to the next page for how to do this) Page 6
Specific Settings for Windows Vista and 7 Windows Vista and Windows 7 have different security access levels compared to 2000 & XP. This will require you to make changes to the User Account Control settings to allow the SSL VPN client to function correctly. The procedure is slightly different for Vista and 7 as follows: Windows Vista From the Start button, open the Control Panel and then open the User Accounts settings. Click on the link labelled Turn User Account Control On or Off Refer to the screen shot below. Deselect the tick box to turn off UAC and click on the OK button. You will now need to reboot your PC for the setting to take effect. Windows 7 From the Start button, open the Control Panel and then open the Action Center. Click on the link labelled Change the Access Control Settings Refer to the screen shot below. Move the slider down to the Never notify position and click on the OK button. Reboot your PC if prompted to do so. If you are unable to alter these settings then you may not have sufficient user priveleges. You will need to contact your IT administrator to modify them or change your access level. Page 7
Testing the Connection With the VPN Client connected to the WestermoConnect server you should now be able to communicate with the remote router, providing it is powered and indicating a healthy connection status. Using a ping is the easiest way to prove connectivity to the router and/or end device. Using the example below this section will show how to test communications through to the end device. VPN Client Connected SSL VPN Tunnel Windows PC SSL VPN Tunnel Router 172.16.7.1 Data Logger 172.16.7.2 WestermoConnect Internet Sending a ping to the remote IP adddress is the quickest way to establish if the communications path is working. To open a command window click on the Start button and click on Run. Enter CMD in the Open: field and click OK (With Vista and 7 you can enter CMD directly from the search dialog box). Now type the command ping 172.16.x.x (where x.x is the address of your own router) and check that a reply is received. It is not uncommon for the first ping to fail due to a delay while the route is discovered, but subsequent pings should reply. Wireless routers will have a relatively high ping response time compared to an ADSL or corporate LAN router connection. The remote device attached to the router must have an IP address that is part of the same subnet as the router. Available addresses will be advised on the letter that accompanies the router. It must also have a gateway address programmed to be reachable through a routed network. The gateway address will be the IP address of your router. In the above example the data logger will have a gateway address of 172.16.7.1, as this provides the route back to the PC. Once this has been done the remote device should also be reachable with a ping in the same manner as the router. Page 8
Troubleshooting Cannot install or run the VPN client This is likely to be a permissions issue within Windows. If the OS is Vista or 7 run the installation.exe file as an administrator. VPN client does not connect (no green light) Check that the username and password are correct. Check the PC has access to the internet Check if your network uses a proxy server to access the internet. If it does you may need to set the VPN client to use the browser settings to gain internet access. VPN client connects, but no access to remote network Ensure the remote router is powered and connected to the WestermoConnect service. Check that the routing table on the PC has been updated to include the remote network. From a command window type route print and see if the 172.16.0.0 network appears in the list (see screen shot below). If it is not listed and your OS is Vista or 7, refer to page 7 and ensure this setting has been completed. Cannot access the remote device Ensure that the remote device has an IP address on the same subnet as the router and that the gateway address has been configured. Use a ping to determine successful communications in the first instance. If you are having any problems, or need assistance with your WestermoConnect service, please contact us for free Technical Support: Phone: +44 (0)1489 580585 E-mail: technical@westermo.co.uk Page 9
REV. 1-2012-06