58
• InRight AddressenterthepublicIPorDNSaddressoftheremoteendofthetunnel(onlyiftheremoteendhasastatic
ordyndnsaddress).Otherwiseleavethisblank
• IftheVPNgatewayisservingasaVPNgatewaytoalocalsubnet(e.g.theConsoleServerhasaManagementLAN
congured)entertheprivatesubnetdetailsinLeft Subnet.UsetheCIDRnotation(wheretheIPaddressnumberis
followedbyaslashandthenumberof‘one’bitsinthebinarynotationofthenetmask).Forexample192.168.0.0/24
indicatesanIPaddresswheretherst24bitsareusedasthenetworkaddress.Thisisthesameas255.255.255.0.If
theVPNaccessisonlytotheconsoleserveritselfandtoitsattachedserialconsoledevicesthenleaveLeft Subnet blank
• IfthereisaVPNgatewayattheremoteend,entertheprivatesubnetdetailsinRight Subnet.AgainusetheCIDR
notation and leave blank if there is only a remote host
• SelectInitiate Tunnel if the tunnel connection is to be initiated from the Left console server end. This can only be
initiatedfromtheVPNgateway(Left)iftheremoteendwasconguredwithastatic(ordyndns)IPaddress
• ClickApply to save changes
Note: It is essential the configuration details set up on the Console Server (referred to as the Left or Local host) exactly
matches the set up entered when configuring the Remote (Right) host/gateway or software client.
Chapter 4: Serial Port, Device and User Configuration
4.10 OpenVPN
ConsoleServersalsoincludeOpenVPNwhichisbasedonTSL(TransportLayerSecurity)andSSL(SecureSocketLayer).
WithOpenVPN,itiseasytobuildcross-platform,point-to-pointVPNsusingx509PKI(PublicKeyInfrastructure)orcustom
configuration files.
OpenVPNallowssecuretunnelingofdatathroughasingleTCP/UDPportoveranunsecurednetwork,thusprovidingsecure
access to multiple sites and secure remote administration to a console server over the Internet.
OpenVPNalsoallowstheuseofDynamicIPaddressesbyboththeserverandclientthusprovidingclientmobility.Forexample,
anOpenVPNtunnelmaybeestablishedbetweenaroamingwindowsclientandaConsoleServerwithinadatacentre.
CongurationofOpenVPNcanbecomplexsoTrippLiteprovidesasimpleGUIinterfaceforbasicsetupasdescribedbelow.
HoweverformoredetailedinformationonconguringOpenVPNAccessserverorclientrefertotheHOWTOandFAQsat
http://www.openvpn.net