Overview

 

Secure Sockets Layer (SSL) VPN is an emerging technology that provides remote-access VPN capability. SSL VPN has some unique features when compared with other existing VPN technologies. Most noticeably, SSL VPN uses SSL protocol and its successor, Transport Layer Security (TLS), to provide a secure connection between remote users and internal network resources.


OpenVPN is use to established vpn connection from iPad and iPhone.


OpenVPN is an open-source security protocol that creates secure point-to-point connections in routed and remote access facilities. Here’s how you can setup OpenVPN on your iPad and iPhone:


Scenario



Prerequisite


This configuration consists of two (2) sections.

A. UTM Configuration

B. IPad and IPhone Configuration


A. UTM Configuration


We will have to create four VPN rules for establishing VPN in either inter-zone or custom rule.

 1. LAN -VPN 

 2. VPN-LAN

 3. UTM-VPN

 4. VPN-UTM

 



Select services as per your requirement or you can select any services and click on OK




Configuring SSL VPN Server Settings


Before establishing SSL VPN connections you need to configure the SSL VPN server on Seqrite UTM. The client will send request to this server and the server will authenticate the client as per the authentication settings. After a successful authentication the connection for communication will be established.


1. Navigate to VPN > SSL > Server Settings. The following screen appears.




2. Select a Certificate Authority for SSL VPN and set it as default using the Set Default button. If there is no Certificate Authority, you can also create a certificate using the ADD(+) button.



  • Enter Nickname and Common name
  • Select the created certificate
  • Select the Country and enter State
  • Enter validity of certificate.




3. By default the SSL VPN Server is disabled. Select the Enable option to enable the Server.



4. The following points explains the fields on page, configure as required.



  1. Interface:  Select the Interface from the drop-down list. This is the WAN interface on which the SSL VPN will accept connections.
  2. Port:-Select only one of the port from the following:

  3. SSLVPN-TCP: Select this protocol if remote SSL VPN server is running on TCP.Default port for TCP is 1194. Customer can add customized port for SSL VPN, and configure firewall rules accordingly.

  4. SSLVPN-UDP: Select this protocol if remote SSL VPN server is running on UDP.

  5. Virtual IP Pool: Enter the Network address of the Virtual IP Pool, these addresses will be assigned to the SSL VPN clients. Select its Subnet.

  6. Advanced Options (Click on + to expand option)

    5. Select below Parameters as per your need

  • Cipher: A cipher (or cipher) is an algorithm for performing encryption or decryption. Select the type of Cipher you want to use for your network.(cipher algorithms are 3DES,AES128,AES192,AES256 and BLOWFISH)
  • Hash Algorithm: Select the data hash algorithm for your network.(Hash algorithms are MD5,SHA1)
  • Diffie–Hellman Key size: The Diffie–Hellman key exchange parameter allows two parties that have no prior knowledge of each other to jointly establish a shared secret key over an insecure communications channel. You can select the length of the DH parameter.
  • Maximum Clients: The maximum number of clients that can connect to the VPN network.(Bydefault 75)
  • VPN Compression:  Select this parameter if you want to compress the data on your SSL VPN.
  • Duplicate CN: Select this option if you want concurrent connections for each user.
  • Client to Client: Select this option to allow connectivity between any pair of remote systems.
  • Dead Peer Detection: Select this option if you want Seqrite UTM to detect offline remote systems.(Bydefault HELLO=30 sec and HOLD=120 sec)
  • Type of Service (Tos): Select this option to preserve the ToS bit for SSL VPN traffic.



6. After entering all the required information, click Apply .




Configuring Single PC remote access for SSL VPN


1. Navigate to VPN  > SSL > Remote Access. The SSL VPN Remote access connections list is displayed. The current connections are displayed in the list.

2. Click the + (Add) icon. The Remote Access Add configuration page is displayed.




3. Enter the Connection Name.



4. Enter the Username and Password in the designated text boxes. Retype the Password in Confirm Password text box. These credentials are used for authentication.



5. Select “Local networks” that you want to configure for Remote Access from the networks that are listed.



6. Add “Additional Commands” if any.


 

7. Click Apply.



8. Once the user is created turn one “Status” and Click on “Download” option.



9. Select “Click here to download a zip containing only keys and configuration” and download the .tar file.




2. IPad / IPhone Configuration 


1. To configure OpenVPN on iOS device you need to install OpenVPN Connect App and download the OpenVPN files.



2. Open App Store and search for OpenVPN Connect App from your iOS device to download / install it


3. Perform the following:

  1. Connect your iOS device to PC / Mac and launch iTunes
  2. From iTunes Apps section select OpenVPN App
  3. Copy this tar file to PC from previous (Section: Configuring Single PC remote access for SSL VPN, Step: 9)
  4. Extract .tar file. This tar file contains Ca.crt, Client.crt, Client.key and Client.ovpn.  
  5. Drag and drop those files from your PC to OpenVPN Documents of your iPad / iPhone.



6. Now tap on OpenVPN app from your iPad / iPhone



7. Tap on "+" icon to add profiles one by one.



8. Insert Username and Password tap on Save button and turn on VPN.



9. Once VPN will connect, VPN Icon will appear on status



10. Now UTM site, status will automatically turn to Active state and local services of this network can be accessible from iPad / iPhone.



For assistance please write us @ 
UTMSupport@Seqrite.com