Users Manual Part 2
Device Configuration
VPN – OpenVPN (OpenVPN Server – TAN Mode)
165
BEC 4700A / 4700AZ User Manual
Local Access Range
IP Address / Netmask: Enter local OpenVPN Server’s LAN network IP address and Netmask.
Certification
Local Certificate / Trusted CA Index: OpenVPN mutually authenticate the server and client
based on certificates and CA. Select a certificate and CA.
To import certificates and CAs, go to Maintenance >> Certificate Management to upload files.
Otherwise, select Default certificate and CA.
Cryptographic Suite
Cipher: OpenVPN uses all the ciphers available in the OpenSSL package to encrypt both the
data and channels. Select an encryption method.
Hash: To establish the integrity of the datagram and ensures it is not tampered with in
transmission. There are options: Message Digest 5 (MD5) and Secure Hash Algorithm (SHA1,
SHA256). SHA1 is more resistant to brute-force attacks than MD5. However, it is slower.
Compression: Choose adaptive to use the LZO compression library to compress the data
stream.
Keepalive: Check the box to enable the keepalive feature. The system will automatically send
ping packet to remote peer to keep the tunnel active.
Interval: Set the keep-alive Interval, unit in seconds. Default is 10 seconds. Valid interval range
is from 0 to 3600 seconds.
Timeout: Re-establish tunnel if no responses from peer network after timeout period expires.
Default is 120 seconds.
Click Save to apply settings.










