Configuration via web interface (menu "LAN (ext)", page "OpenVPN client")
In order to use the OpenVPN client for a connection, check the checkbox
"Activate OpenVPN client".
In order to define the IP address or the domain name of the remote
terminal, which you use to have the router establish the OpenVPN
connection, enter an IP address or a domain name in the field "IP address
or domain name of remote site".
Optionally, an alternative remote terminal can be defined, which will be
used to establish the VPN connection, if the remote terminal configured
above is not available. Enter an IP address or domain name into the
"Alternative remote site" field for this.
In order to define the local port at the EBW-E100 as well as the port at
the remote terminal, enter a value for the required port into the entry
fields "Tunnelling over port (local / remote)".
The OpenVPN transmission protocol is selected with the radio buttons
"UDP" or "TCP". We recommend to use UDP to minimize latency.
If the remote terminal can only be accessed via a proxy server, enter its
IP address or domain name into the "IP address or domain name of proxy
server" field, select its type using the "HTTP" or "SOCKS5" radio buttons
and enter its port into the "Port" field. If the proxy server requires an
authentication, enter the access data into the "User name" and
"Password" fields.
In order to set a default route, check the checkbox "Set default route
(redirect-gateway)". The complete data traffic will be routed through the
tunnel then.
It is not obligatory to provide the local port and the IP address of the
OpenVPN connection. If you want to leave the use of ports and the IP
address free, uncheck the checkbox "Bind to local address and port".
In order to enable remote OpenVPN terminals to change its IP during a
connection ("Floating"), check the checkbox "Remote terminal is allowed
to change its IP address (float)". This setting is activated by default.
In order to enable or disable LZO compression, check or uncheck the
checkbox "Activate LZO compression". If already strongly compressed
data (e.g. jpg) is transmitted, the compression will have hardly any effect;
however, if compressible data (e.g. text) is transmitted, the compression
may significantly reduce the transmitted volume of data. Switch the
compression off, if the remote terminal does not support LZO
compression.
In order to mask the packets with the virtual tunnel IP address, check the
checkbox "Masquerade packets before tunnelling". The recipient of the
packets sees the IP address of the tunnel end as sender then, not the
address of the original sender.