AZTCOFW / DOCUMENTATION
OpenVPN Remote Access Configuration Example
Configuration guides, troubleshooting and practical advice for AZTCOFW.
Articles
17 resultsAdding a RADIUS Server
If no RADIUS servers exist, or Add new RADIUS server was selected, a screen is presented with the options needed to add a new server. If there is any uncertainty about the settings, consult the RADIUS server administrato
Adding a Server Certificate
This screen creates a new server certificate which will be used to verify the identity of the server to the clients. The server certificate will be signed by the certificate authority chosen or created previously in
Adding a User with a Certificate
If the mode has been left at the wizard’s default or on a mode that includes local user authentication, a user must be created in the user manager. Navigate to System > User Manager Click + To add a user Fill in Usernam
Adding an LDAP Server
If no LDAP servers exist or Add new LDAP server is chosen a screen will be presented with the options needed to add a new server. Many of these options will depend on the specific LDAP directory configuration and structu
Adjustments
Some settings are not presented in the wizard but might be a better fit for some situations than the defaults chosen by the wizard. Server Mode The OpenVPN Server Mode allows selecting a choice between requiring Certific
Before Starting The Wizard
Before starting the wizard to configure the Remote Access Server, there are some details that must be planned. Determine an IP addressing scheme An IP subnet must be chosen for use by the OpenVPN clients themselves. This
Choose Authentication Type
On the first screen of the OpenVPN Remote Access server wizard, choose a method for user authentication. The choices available for Authentication Backend Type are Local User Access , LDAP , and RADIUS . If an existing au
Choosing a Certificate Authority
If there is an existing Certificate Authority defined on the AZTCO-FW firewall, it may be chosen from the list. To create a new Certificate Authority, choose Add new CA . If no Certificate Authorities are defined, this s
Choosing a RADIUS Server
If there is an existing RADIUS server defined on the AZTCO-FW firewall, choose it from the list. To use a different RADIUS server, instead choose Add new RADIUS server . If no RADIUS servers are defined on AZTCO-FW, this
Choosing a Server Certificate
If there is an existing Certificate defined on the AZTCO-FW firewall, it may be chosen from the list. To create a new Certificate, choose Add new Certificate . If no Certificates are defined, this step is skipped.
Choosing an LDAP Server
If an LDAP server is already defined on the AZTCO-FW firewall it may be chosen from the list. To use a different LDAP server instead choose Add new LDAP server . If there are no LDAP servers defined, this step is skipped
Configuring OpenVPN Server Settings
The options on this step of the wizard configure each aspect of how the OpenVPN server itself will behave as well as options which are passed on to clients. The options presented here are the same as those discussed prev
Creating a Certificate Authority
This step presents all of the necessary fields to create a new certificate authority (CA). Every option on this page is required, and all fields must be filled out correctly to proceed. The CA is used to establish a trus
Finishing the Wizard
Click Finish and the wizard is now complete; The tunnel is fully configured and ready for client connections. From here the next steps are to add users and configure client devices. If adjustments to the automatically ge
Firewall Rule Configuration
As with other parts of the firewall, by default all traffic is blocked from connecting to VPNs or passing over VPN tunnels. This step of the wizard adds firewall rules automatically to allow traffic to connect to the VPN
OpenVPN Client Export Package
The OpenVPN Client Export Package allows exporting configurations formatted for a wide variety of platforms. It also allows exporting a pre-packaged Windows installer executable which includes the configuration bundled i
Verifying the Setup
Look at firewall rules ( WAN and OpenVPN tabs) WAN tab rule should pass from any to the OpenVPN port on the WAN address OpenVPN tab rule should allow anything from any/to any