OxyGEN
mini
Office
Administrator’s Guide
Server Mode
When OxyGEN miniOffice is configured to run in Server mode, the configuration page presented in
Figure 11.5 appears. When using a Routed type of tunnel, to configure your device, you must specify
the
Network
and
Netmask
values for the subnet used as an IP address pool for the connected clients.
Each remote client that connects to the OxyGEN SSL-VPN server will automatically acquire an IP address
from this pool. If, on the other hand, you have selected a Bridged type of tunnel, no IP addressing info
is required and you must only select which LAN Service is going to be bridged over the SSL VPN tunnel.
The DHCP server of the selected Service is also going to be used for providing IP addressing information
to any requests received over the tunnel. Once you have entered the correct values, click
Apply
in
order to activate your settings.
The final step in order to finish setting up the SSL-VPN server, is to define remote users and generate
the corresponding certificates. To this end click the
Manage
key under the
Users
heading. The screen
presented in Figure 11.6 appears. The table at the top of the page, displays a list of the configured users.
You can Revoke configured users by clicking on the corresponding
icon of
Action
column.
In order to add a new remote user, enter the username under the
Add New User
heading and click
the
Save
key. The new user is added and a message window opens prompting you to save a zip file.
This zip file contains the certificates corresponding to the added user. Save the file and give it using a
secure method (e.g. not via e-mail) to the new remote user. The zip file contains all information needed
in order to connect to the SSL-VPN server running on your OxyGEN miniOffice.
Note
There is no way of re-generating the certificates corresponding to a configured SSL VPN
username. In case you want to do so, the only option is to revoke the username and
then add it again.
Client Mode
When OxyGEN miniOffice is configured to run in Client mode, the following fields appear in the SSL-VPN
web configuration page presented in Figure 11.4. The first task is to specify the hostname or IP address
of the SSL-VPN server in the
Host/IP
field. When using a Routed type of tunnel, it is also possible to select
if
NAT
(Network Address Translation) is going to be used over the tunnel.
This way, once the server
assigns an IP address to the client, all devices in the LAN behind the client OxyGEN miniOffice are going
to appear to the server as if they have the client’s tunnel IP address. If, on the other hand, you have
selected a Bridged type of tunnel, you must only select which LAN Service is going to be bridged over
the SSL VPN tunnel. Once you have entered the correct values, click
Apply
in order to activate your
settings.
In order to finish with the secure connection to the SSL-VPN server, you will also need to install the
corresponding certificate files. These certificates must be provided to you by the administrator of the
SSL-VPN server. In the case of an OxyGEN miniOffice acting as the server, this is the zip file that was
Gennet s.a.
201