Moxa ioPAC 8500-5-M12-C-T [55/69] Moxa c programmable rtu controllers managing communications

Moxa ioPAC 8500-2-RJ45-C-T [55/69] Moxa c programmable rtu controllers managing communications
Moxa C Programmable RTU Controllers Managing Communications
4-18
Create a configuration file named B-tap0-br.conf and an executable script file named B-tap0-br.sh on
OpenVPN B.
# point to the peer
remote 192.168.8.173
dev tap0
secret /etc/openvpn/secrouter.key
cipher DES-EDE3-CBC
auth MD5 tun-mtu 1500
tun-mtu-extra 64
ping 40
up /etc/openvpn/B-tap0-br.sh
#----------------------------------Start------------------------------
#!/bin/sh
# value after-net” is the subnet behind the remote peer
route add -net 192.168.2.0 netmask 255.255.255.0 dev br0
#---------------------------------- end ------------------------------
NOTE: Select cipher and authentication algorithms by specifying “cipher” and “auth”. To see with
algorithms are available, type:
# openvpn --show-ciphers
# openvpn --showauths
4. Start both of OpenVPN peers,
# openvpn --config A-tap0-br.conf&
# openvpn --config B-tap0-br.conf&
If you see the line “Peer Connection Initiated with 192.168.8.173:5000” on each machine, the connection
between OpenVPN machines has been established successfully on UDP port 5000.
5. On each OpenVPN machine, check the routing table by typing the command:
# route
Destination Gateway Genmsk Flags Metric Ref Use Iface
192.168.4.0 * 255.255.255.0 U 0 0 0 br0
192.168.2.0 * 255.255.255.0 U 0 0 0 br0
192.168.8.0 * 255.255.255.0 U 0 0 0 eth0
Interface eth1 is connected to the bridging interface br0, to which device tap0 also connects, whereas the
virtual device tun sits on top of tap0. This ensures that all traffic from internal networks connected to
interface eth1 that come to this bridge write to the TAP/TUN device that the OpenVPN program monitors.
Once the OpenVPN program detects traffic on the virtual device, it sends the traffic to its peer.
6. To create an indirect connection to Host B from Host A, you need to add the following routing item:
route add net 192.168.4.0 netmask 255.255.255.0 dev eth0
To create an indirect connection to Host A from Host B, you need to add the following routing item:
route add net 192.168.2.0 netmask 255.255.255.0 dev eth0
Now ping Host B from Host A by typing:
ping 192.168.4.174
A successful ping indicates that you have created a VPN system that only allows authorized users from one
internal network to access users at the remote site. For this system, all data is transmitted by UDP packets
on port 5000 between OpenVPN peers.
7. To shut down OpenVPN programs, type the command:
# killall -TERM openvpn

Содержание

Скачать