User`s guide

CONFIGURATION
54
In this configuration equipment wired behind the router defines the address Server IP
Address. The router replies, while PING on address of SIM card. Access on web interface
of the equipment behind the router is possible by the help of Port Forwarding, when behind
IP address of SIM is indicating public port of equipment on which we want to come up.
At demand on port 80 it is surveyed singles outer ports (Public port), there this port isn't
defined, therefore at check selection Enable remote http access it automatically opens
the web interface router. If this choice isn't selected and is selected volition Send all
remaining incoming packets to the default server fulfill oneself connection on induction IP
address. If it is not selected election Send all remaining incoming packets to default server
and Default server IP address then connection requests a failure. If it is necessary to set
more than 8 rules for NAT, then it is possible to insert into start up script following script.
If necessary set more than twelve rules for NAT, then is possible insert into start up
script following script:
iptables -t nat -A napt -p tcp --dport [PORT_PUBLIC] -j DNAT --to-destination
[IPADDR]:[PORT1_PRIVATE]
Concrete IP address [IPADDR] and ports numbers [PORT_PUBLIC]
and [PORT1_PRIVATE] are filled up into square bracket.
6.12. OpenVPN Tunnel Configuration
OpenVPN tunnel configuration can be called up by option OpenVPN item
in the menu. OpenVPN tunnel allows protected connection of two networks LAN to the one
which looks like one homogenous. In the OpenVPN Tunnels Configuration window are two
rows, each row for one configured OpenVPN tunnel. The column Create switches on tunnels,
other columns contain values view set in the OpenVPN Tunnel Configuration windows;
configuration is possible by the Edit button.
In the window can be defined tunnel name (Description) and Protocol, by
which the tunnel will communicate. At choice is UDP, TCP server or TCP client protocol
which has to have defined port protocol (UDP port nebo TCP port). On off - side tunnel IP
address (Remote External IP Address), address nets behind off - side tunnel (Remote
Subnet), mask nets behind off - side tunnel (Remote Subnet Mask). By parameter Redirect
Gateway is possible to redirect all traffic on Ethernet. Parameter Local Interface IP Address
defines local interface IP address, parameter Remote Interface IP Address defines
the interface IP address of the off-side tunnel. Parameter Ping Interval defines the time
period after which it sends a message to off-side and by parameter Ping Timeout waits
on message from off-side tunnel. For OpenVPN tunnel right verify parameter Ping Timeout
has to be bigger than Ping Interval. Parameter Renegotiate Interval sets renegotiate period
(reauthorization) of the OpenVPN tunnel. This parameter is possible to set only
at username/password authentication or at X.509 certificate using. By parameter Max
Fragment Size it is possible to define maximum sending packet size. Sending data
is possible compress by lossless LZO compressions by parameter Compression,
compression has to be on both tunnel ends. By parameter NAT Rules it is possible to apply