D-Link DSR-Series User Manual 137
Section 7 - VPN
Field Description
OpenVPN Click On/Oī button to start or stop the OpenVPN process. By default, this option is disabled.
Mode Select Server.
VPN Network Enter the IP network for the VPN.
VPN Netmask Enter the netmask.
Duplicate CN Toggle On to allow a same certiīcation for multiple clients.
Port Enter what port to use. The default port is 1194.
Tunnel Protocol Select either TCP or UDP.
Encryption Algorithm Select the encryption algorithm from the drop-down menu.
Hash Algorithm Select the hash algorithm from the drop-down menu. The options are SHA1, SHA256, SHA512.
Tunnel Type
Select either Full Tunnel or Split Tunnel. Full Tunnel mode just sends all traīc from the client across the
VPN tunnel to the router. Split Tunnel mode only sends traīc to the private LAN based on pre-speciīed
client routes. If you select Split Tunnel, refer to āLocal Networksā on page 147 to create local networks.
Client to Client
Communication
Enable this īeld to allow openvpn clients to communicate with each other in split tunnel case. By default,
it is disabled.
User Based Auth
This option is introduced to provide the additional authentication method using username/password.
Disabled by default.
Certiīcate Veriīcation
This method does not require the client certiīcate, client will authenticate using the username/password
only. Enabled by default.
Certs Proīle
Select the proīle which has list certiīcates uploaded for the conīgured mode server/client. By default,
the default proīle will be selected which has both server and client certiīcates.
TLS Authentication Key
Enabling this adds Tls authentication which adds an additional layer of authentication. Can be checked
only when the tls key is uploaded. Disabled by default.
TLS Key Select the type of tls certiīcate name.
Invalid Client
Certiīcates
Enabling this adds facility to block invalid client certiīcate. This feature requires crl certiīcate which
contains list of client certiīcates to be blocked. Please upload crl certiīcate in OpenVPN Authentication
page. Disabled by default
CRL Certiīcates Select the type of crl certiīcate name.
Save Click Save to save and activate your settings.
Cancel Click Cancel to revert to previous settings.