Administrator’s Guide for SIP-T46G IP Phone
162
more prevalent due to the benefits: scalability, reliability, convenience and security.
There are two types of VPN access: remote-access VPN (connecting an individual
device to a network) and site-to-site VPN (connecting two networks together).
Remote-access VPN allows employees to access their company's intranet from home or
outside the office, and site-to-site VPN allows employees in geographically separated
offices to share one cohesive virtual network. VPN can be also classified by the
protocols used to tunnel the traffic. It provides security through tunneling protocols:
IPSec, SSL, L2TP and PPTP.
The IP phones support SSL VPN. SSL VPN provides remote-access VPN capabilities
through SSL. OpenVPN is a full featured SSL VPN software solution that creates secure
connections in remote access facilities. It
is designed to work with the
TUN/TAP
virtual
networking interface. TUN and TAP are virtual network kernel devices. TAP simulates a
link layer device and provides a virtual point-to-point connection. TUN simulates a
network layer device and provides a virtual network segment. The IP phones support
using OpenVPN to achieve the VPN feature. To prevent disclosure of private information,
tunnel endpoints must authenticate each other before secure VPN tunnel is established.
After the VPN feature is configured properly on the IP phone, the IP phone acts as a VPN
client and uses the certificates to authenticate the VPN server.
To use the VPN feature, the compressed package of VPN-related files should be
uploaded to the IP phone in advance. The file format of the compressed package must
be .tar. The VPN-related files are: certificates (ca.crt and client.crt), key (client.key) and
the configuration file (vpn.cnf) of the VPN client. For more information on how to
package a tar file, refer to
VPN Feature on Yealink IP Phones
.
Procedure
VPN can be configured using the configuration files or locally.