User's Manual

EnRoute50x/51x User’s Guide
TR0153 Rev. D2
86
Figure 38. NAT setting
11.3 VPN Access to a Mesh Gateway
An EnRoute500 configured as a gateway can establish a VPN connection to an OpenVPN
server. This VPN connection provides the following capabilities:
Any node in the mesh can be contacted directly from a remote host, even when NAT is
enabled on the gateway node. This allows remote access to nodes to monitor their
behavior or reconfigure them
A secure path between the mesh and a host, which can be used to monitor and reconfigure
the mesh, is established. The control and status traffic passing between the mesh and the
host is protected if it passes over a public network at any point.
The state of the VPN client on the EnRoute500 is set with the Enable VPN parameter. The IP
address of the VPN server and its port are specified with the VPN Server and VPN Port
parameters. Note that the VPN server parameter can either be an IP address or a resolvable
host name.
CLI
The example below shows how to enable the VPN connection („vpn.enable‟ in the „sys‟
interface) and set the server and port parameters („vpn.server‟ and „vpn.port‟ in the „sys‟
interface).