This shows you the differences between two versions of the page.
Next revision | Previous revision | ||
wiki:network_mana:secure_network:ipsec_openvpn [2023/03/02 15:19] gja created |
wiki:network_mana:secure_network:ipsec_openvpn [2023/03/28 15:46] (current) gja [OpenVPN] |
||
---|---|---|---|
Line 1: | Line 1: | ||
====== IPsec / OpenVPN ====== | ====== IPsec / OpenVPN ====== | ||
+ | |||
+ | This section does not concern WMC server. The Kerlink WMC already provides OpenVPN. | ||
The KerOS firmware comes with strongSwan and OpenVPN clients pre-installed. The credentials, however, need to be stored in a very specific way, described in this page. | The KerOS firmware comes with strongSwan and OpenVPN clients pre-installed. The credentials, however, need to be stored in a very specific way, described in this page. | ||
Line 63: | Line 65: | ||
- [[wiki:network_mana:secure_network:keros_4.x:vpn_server_configuration|VPN server configuration]]: VPN server configuration | - [[wiki:network_mana:secure_network:keros_4.x:vpn_server_configuration|VPN server configuration]]: VPN server configuration | ||
- [[wiki:network_mana:secure_network:keros_4.x:setting_up_the_vpn_client|Setting up the VPN client]]: VPN client configuration | - [[wiki:network_mana:secure_network:keros_4.x:setting_up_the_vpn_client|Setting up the VPN client]]: VPN client configuration | ||
- | - [[wiki:network_mana:secure_network:keros_4.x:running_the_application]]: VPN client startup | + | - [[wiki:network_mana:secure_network:keros_4.x:running_the_application|Running the application]]: VPN client startup |
Line 75: | Line 77: | ||
==== OpenVPN ==== | ==== OpenVPN ==== | ||
- | On keros 5.x, unlike keros 4.x, OpenVPN is independant from ProvenCore and can be used like as on any linux system. | + | On keros 5.x, unlike keros 4.x, OpenVPN is independant from ProvenCore and can be used like as on any linux system. There is no need to encrypt and store passwords, keys and certificates in the TrustZone. |
There may be some limitations at the level of the Cipher depending on the version used. Use the command below to know the supported cipher : | There may be some limitations at the level of the Cipher depending on the version used. Use the command below to know the supported cipher : |