VPN with INSYS routers Configuring OpenVPN server with authentication via static key. Configuration Guide



Similar documents
VPN with INSYS routers Configuring OpenVPN server with certificate-based authentication. Configuration Guide

VPN with INSYS routers Connecting two Siemens S7-300 in different networks. Configuration Guide

VPN with INSYS Connectivity Service OpenVPN Connection to INSYS Connectivity Service under Android. Configuration Guide

VPN with INSYS routers Creating X509.v3 Certificates for VPNs with XCA. Configuration Guide

Configuration Guide. Replacing a Leased Line with INSYS GPRS 5.x serial

INSYS IMON - Monitoring Function Switching an output via SMS. Configuration Guide

How to access peers with different VPN through IPSec. Tunnel

VPN L2TP Application. Installation Guide

ENDIAN Topologies Setup of different Network topologies with Endian Firewalls

Configuration Guide. How to set up the IPSec site-to-site Tunnel between the D-Link DSR Router and the Cisco Firewall. Overview

1 Axis camera configuration IP configuration Setting up date and time Installing an IPS Analytics Application...

Configuring a Check Point FireWall-1 to SOHO IPSec Tunnel

If you have questions or find errors in the guide, please, contact us under the following address:

Configuration Guide. How to set up the IPSec site-to-site Tunnel between the D-Link DSR Router and the Fortinet Firewall. Overview

VPN Configuration Guide Netgear FVS338 / FVX538 / FVS124G

VPN PPTP Application. Installation Guide

VPN Configuration Guide D-Link DFL-200

Configuring a VPN for Dynamic IP Address Connections

CREATING AN IKE IPSEC TUNNEL BETWEEN AN INTERNET SECURITY ROUTER AND A WINDOWS 2000/XP PC

Web Authentication Application Note

How To Configure Apple ipad for Cyberoam L2TP

SSL SSL VPN

VPN Configuration Guide Linksys RV042/RV082

Linking 2 Sites Together Using VPN How To

Astaro User Portal: Getting Software and Certificates Astaro IPsec Client: Configuring the Client...14

VPN Configuration Guide. Cisco Small Business (Linksys) WRV210

VPN Configuration Guide SonicWALL with SonicWALL Simple Client Provisioning

VPN Configuration Guide. Cisco Small Business (Linksys) WRVS4400N / RVS4000

VPN Configuration Guide LANCOM

Configuring Microsoft RADIUS Server and Gx000 Authentication. Configuration Notes. Revision 1.0 February 6, 2003

How To Set Up A Vpn Tunnel Between Winxp And Zwall On A Pc 2 And Winxp On A Windows Xp 2 On A Microsoft Gbk2 (Windows) On A Macbook 2 (Windows 2) On An Ip

Client applications are available for PC and Mac computers and ios and Android mobile devices. Internet

VPN Tracker for Mac OS X

Configuring IPsec between a Microsoft Windows XP Professional (1 NIC) and the VPN router

Astaro Security Gateway V8. Remote Access via SSL Configuring ASG and Client

VPN Configuration Guide DrayTek Vigor / VigorPro

RouteFinder. IPSec VPN Client. Setup Examples. Reference Guide. Internet Security Appliance

VPN Configuration Guide SonicWALL with SonicWALL Simple Client Provisioning

VPN Tracker for Mac OS X

Parallels Plesk Panel. VPN Module for Parallels Plesk Panel 10 for Linux/Unix Administrator's Guide. Revision 1.0

VPN Configuration Guide D-Link DFL-800

How to Create a Basic VPN Connection in Panda GateDefender eseries

VPN. VPN For BIPAC 741/743GE

Sophos UTM. Remote Access via PPTP. Configuring UTM and Client

Using Microsoft Expression Web to Upload Your Site

VPN Configuration Guide. Cisco Small Business (Linksys) RV016 / RV042 / RV082

Astaro Security Gateway V8. Remote Access via L2TP over IPSec Configuring ASG and Client

Configuration Guide. How to set up the IPSec site-to-site Tunnel between the D-Link DSR Router and the Sonicwall Firewall.

Sophos UTM. Remote Access via SSL Configuring Remote Client

How to Connect SSTP VPN from Windows Server 2008/Vista to Vigor2950

Integration Guide. Microsoft Active Directory Rights Management Services (AD RMS) Microsoft Windows Server 2008

ecatcher Talk2M Pro - Remote Connection Quick Start How To

VPN Tracker for Mac OS X

VPN Configuration Guide WatchGuard Fireware XTM

VPN Configuration Guide. Parallels Remote Desktop for Mac

IPSecuritas 3.x. Configuration Instructions. AVM FRITZ!Box. for

VPN Tracker for Mac OS X

User manual Remote access VNC V 0.2

VPN Quick Configuration Guide. Astaro Security Gateway V8

PePWave Surf Series PePWave Surf Indoor Series: Surf 200, AP 200, AP 400

Configuration Guide. How to Configure SSL VPN Features in DSR Series. Overview

White Paper. Installation and Configuration of Fabasoft Folio IMAP Service. Fabasoft Folio 2015 Update Rollup 3

Setting up VPN Access for Remote Diagnostics Support

Verizon Remote Access User Guide

vcloud Director User's Guide

Chapter 6 Virtual Private Networking

Evaluation Board. i-modul and Socket. Manual

Virtual Private Network and Remote Access

How To Configure An Ipsec Tunnel On A Network With A Network Gateways (Dfl-800) On A Pnet 2.5V2.5 (Dlf-600) On An Ipse Vpn

VPN Configuration of ProSafe VPN Lite software and NETGEAR ProSafe Router:

Intel Active Management Technology with System Defense Feature Quick Start Guide

Configuring TheGreenBow VPN Client with a TP-LINK VPN Router

ZyWALL USG-Series. How to setup a Site-to-site VPN connection between two ZyWALL USG series.

Application Note Configuring the UGate 3000 for use with ClipMail Pro and ClipExpress

Enable VPN PPTP Server Function

Hallpass Instructions for Connecting to Mac with a Mac

Integration with Active Directory

How do I set up a branch office VPN tunnel with the Management Server?

VPN Configuration Guide. Juniper Networks NetScreen / SSG / ISG Series

Cox Managed CPE Services. RADIUS Authentication for AnyConnect VPN Version 1.3 [Draft]

Lotus Foundations Start Getting Started

bintec Workshop WAN Partner Configuration Copyright November 8, 2005 Funkwerk Enterprise Communications GmbH Version 0.9

OpenVPN Setup Zeroshell By Cristian Benítez

VPN Configuration Guide. Linksys (Belkin) LRT214 / LRT224 Gigabit VPN Router

How-to: HTTP-Proxy and Radius Authentication and Windows IAS Server settings. Securepoint Security System Version 2007nx

Step-by-Step Setup Guide Wireless File Transmitter

Katana Client to Linksys VPN Gateway

Setting up VPN connection: DI-824VUP+ with Windows PPTP client

VPN Configuration of ProSafe Client and Netgear ProSafe Router:

USG40HE Content Filter Customization

Talk2M ewon Internet Connection How To

Vantage RADIUS 50. Quick Start Guide Version 1.0 3/2005

Remote Access to Embedded WEB by NAT Port Forwarding

Quick Installation Guide DAP Wireless N 300 Access Point & Router

RemotelyAnywhere Getting Started Guide

AXIS Camera Station Quick Installation Guide

How To Establish IPSec VPN between Cyberoam and Microsoft Azure

Configuring Windows 2000/XP IPsec for Site-to-Site VPN

Sophos UTM. Remote Access via SSL. Configuring UTM and Client

How to setup PPTP VPN connection with DI-804HV or DI-808HV using Windows PPTP client

Transcription:

VPN with INSYS routers Configuring OpenVPN server with authentication via static key Configuration Guide

Pos: 1 /Datenkommunikation/Configuration Guide/=== ORGA - Module ===/1 Einführung: Prinzipschaltbild und Ziel/1-0 h1 --- Einführung --- @ 5\mod_1243351890374_91.doc @ 20029 @ 1 Introduction Copyright 2014 INSYS MICROELECTRONICS GmbH Any duplication of this üublication is prohibited. All rights on this publication and the devices are with INSYS MICROELECTRONICS GmbH Regensburg. Trademarks The use of a trademark not shown below is not an indication that it is freely available for use. MNP is a registered trademark of Microcom Inc. IBM PC, AT, XT are registered trademarks of International Business Machine Corporation. Windows is a registered trademark of Microsoft Corporation. Linux is a registered trademark of Linus Torvalds. INSYS is a registered trademark of INSYS MICROELECTRONICS GmbH. The principles of this publication may be transferred to similar combinations. INSYS MICROELECTRONICS GmbH does not assume liability or provide support in this case. Moreover, it cannot be excluded that other effects or results than described here are produced, if other, similar components are combined and used. INSYS MICROELECTRONICS GmbH is not liable for possible damages. Publisher INSYS MICROELECTRONICS GmbH Hermann-Köhl-Str. 22 D-93049 Regensburg Germany Phone +49 941 58692 0 Fax +49 941 58692 45 E-mail URL info@insys-icom.com http://www.insys-icom.com Print 13. Jun. 2014 Item No. - Version 1.4 Language EN 2 Configuring OpenVPN server with authentication via static key EN Vers. 1.4 13. Jun. 2014 www.insys-icom.com

Pos: 5 /Datenkommunikation/Configuration Guide/=== ORGA - Module ===/2 Kurzfassung/2-00 h1 --- Kurzfassung --- @ 5\mod_1259746860297_91.doc @ 22649 @ 1 1 Introduction Introduction General The present publication refers to a combination of selected hardware and software components of INSYS MICROELECTRONICS GmbH as well as other manufacturers. All components have been combined with the target to realize certain results and effects for certain applications in the field of professional data transfer. All components have been prepared, configured and used as described in this publication. Thus, the desired results and effects have been achieved. The exact descriptions of all used components, to which this publication refers, are described in the tables Hardware, Accessories and Software at the end of this publication. The symbols and formattings used in this publication are explained in the correspondent section at the end of this publication. Some configurations or preparations, which are precondition in this publication, are described in other publications. Therefore, always refer to the related device manuals. INSYS devices with web interface provide you with helpful information about the configuration possibilities, if you click on "display help text" in the header. Target of this Publication In the following, you will find a description of how to set up the INSYS router as OpenVPN server with authentication via static keys. Figure 1: Configuring an OpenVPN server with authentication via static keys Configuring OpenVPN server with authentication via static key 3 www.insys-icom.com 13. Jun. 2014 Vers. 1.4 EN

Summary 2 Summary OpenVPN Server Configuration How to configure an INSYS router as OpenVPN server. You will find detailed step by step instructions in the following section. 1. Open in the menu Dial-In / Dial-Out / LAN (ext) / WWAN the page Open- VPN server 2. Check "Activate OpenVPN server" 3. Save settings 4. "Generate a new static key" 5. Check "No authentication or authentication with preshared key" 6. Download static key 7. Enter "IP address or domain name of remote site" 8. Enter local and remote IP address of the VPN tunnel 9. Enter "Netaddress of network behind the VPN tunnel" and "Netmask of network behind the VPN tunnel" if required 10. Save settings 4 Configuring OpenVPN server with authentication via static key EN Vers. 1.4 13. Jun. 2014 www.insys-icom.com

Configuration 3 Configuration Provisions Please prepare the following items before starting the configuration: Connection to the INSYS router INSYS router is connected to power supply and ready for operation. You have access to the INSYS router via your web browser. Date and time are correctly set in the INSYS router. Configuring the OpenVPN Server How to configure the connection data to the remote terminal for the connection set-up of the OpenVPN server. 1. Select in the menu the page OpenVPN server. This page is under the menu item Dial-In, Dial-Out, LAN (ext), or WWAN depending on the used INSYS router. 2. Check the check box "Activate OpenVPN server". 3. Configure the further OpenVPN parameters according to your application. The default settings can be maintained for most applications. It is important that client and server have a consistent configuration. Configuring OpenVPN server with authentication via static key 5 www.insys-icom.com 13. Jun. 2014 Vers. 1.4 EN

Configuration You can check the settings in OpenVPN syntax using the "Display configuration file" link. You can display settings, which might be suitable for the remote terminal, using the "Create sample configuration file for remote terminal" link. 4. Click OK at "Confirm all" to save the settings. The connection data to the remote terminal for the connection set-up of the OpenVPN server is configured with this. Configuring Authentication with Static Key How to configure the authentication with static key for an OpenVPN server and generate the key for the OpenVPN client. 1. Select in the menu the page OpenVPN server. This page is under the menu item Dial-In, Dial-Out, LAN (ext), or WWAN depending on the used INSYS router. 2. Scroll down to No authentication or authentication with preshared key. 3. Click on the link "Generate a new static key". A new static key is generated and a green check mark appears instead of the red "X" at "... preshared key available ". 6 Configuring OpenVPN server with authentication via static key EN Vers. 1.4 13. Jun. 2014 www.insys-icom.com

Pos: 12 /Datenkommunikation/Configuration Guide/=== ORGA - Module ===/5 Verwendete Komponenten / Weiterführende Informationen/5-0 h1 --- Verwendete Komponenten --- @ 5\mod_1253000236681_91.doc @ 21647 @ 1 No authentication will be used if no static key is present. This is not recommended and only useful for test purposes because the data sent through the tunnel will not be encrypted without authentication. OpenVPN client and OpenVPN server require the same static key! Configuration 4. Click on the blue arrow behind "Preshared key available" to download the generated static key and save it. This static key must also be uploaded to the client to allow a connection. You can also use an already existing static key by uploading this in the "Upload key or certificates" section. The same key must also be present on the client. 5. Select the option "No authentication or authentication with preshared key". 6. If necessary, adjust the OpenVPN client data at "IP address or domain name of remote site". This may be necessary, if this IP address is in a used address range. This IP address should always be in an unused, private address range. This information may not be omitted. 7. Enter the IP address of the local tunnel end into the "IP address of VPN tunnel local" field and the IP address of the remote tunnel end into the "IP address of VPN tunnels remote" field. These IP addresses must be swapped at the VPN remote terminal of the client, i.e. the address, which is the local tunnel end at the server, is the remote tunnel end at the client, and vice versa. The default settings can be used here in most cases. 8. If required, enter the network address of the network, to which the VPN tunnel is to be established, into the "Netaddress of the network behind the VPN tunnel" field and the netmask of this network into the "Netmask of network behind the VPN tunnel" field. This is only necessary, if the IP addresses are in a network, which is already used either local or at the remote terminal. In this case, the IP address of a network is an address ending with "0", e.g. 192.168.200.0. The network mask in this case is 255.255.255.0. 9. Click OK at "Confirm all" to save the settings. The authentication via static key is configured with this. Configuring OpenVPN server with authentication via static key 7 www.insys-icom.com 13. Jun. 2014 Vers. 1.4 EN

Pos: 14 /Datenkommunikation/Notizen - Leere Seite zum Auffüllen auf Seitenumfang "x mal 4" @ 5\mod_1242998978108_91.doc @ 19977 @ Used Components 4 Used Components Please observe: The power supply units required to operate devices are not listed here in detail. Take care for a provision at the site, if they are not part of the scope of delivery. Hardware Description Manufacturer Type Version Router INSYS INSYS router Firmware 2.12.1 Table 1: Used hardware Software Description Manufacturer Type Version Operating system Microsoft Windows 7 SP1 Browser Mozilla Firefox 30 Table 2: Used software 8 Configuring OpenVPN server with authentication via static key EN Vers. 1.4 13. Jun. 2014 www.insys-icom.com

=== Ende der Liste für Textmarke Inhalt === 5 Notes Notes Configuring OpenVPN server with authentication via static key 9 www.insys-icom.com 13. Jun. 2014 Vers. 1.4 EN

Notes 10 Configuring OpenVPN server with authentication via static key EN Vers. 1.4 13. Jun. 2014 www.insys-icom.com

Notes Configuring OpenVPN server with authentication via static key 11 www.insys-icom.com 13. Jun. 2014 Vers. 1.4 EN

Germany INSYS MICROELECTRONICS GmbH Hermann-Köhl-Str. 22 93049 Regensburg Germany Phone +49 941 58692 0 Fax +49 941 58692 45 E-mail URL info@insys-icom.com www.insys-icom.com Great Britain INSYS MICROELECTRONICS UK Ltd. The Venture Centre Univ. of Warwick Science Park Sir William Lyons Road Coventry, CV4 7EZ Great Britain Phone +44 2476 323 237 Fax +44 2276 323 236 E-mail URL info@insys-icom.co.uk www.insys-icom.co.uk Czech Repulic INSYS MICROELECTRONICS CZ, s.r.o. Slovanská alej 1993 / 28a 326 00 Plzen-Východní Předměstí Czech Republic Phone +420 377 429 952 Fax +420 377 429 952 Mobile +420 777 651 188 E-mail URL info@insys-icom.cz www.insys-icom.cz