21.6Example of a more complex Kerio VPN configuration

Set the IP address of this interface (172.16.1.1) as a primary DNS server for the WinRoute host’s interface connected to the LAN 1 local network. It is not necessary to set DNS at the interface connected to LAN 2.

Set the IP address 172.16.1.1 as a primary DNS server also for the other hosts.

4.Enable the VPN server and configure its SSL certificate (create a self-signed certificate if no certificate provided by a certification authority is available).

Note: A free subnet which has been selected is now specified automatically in the VPN network and Mask entries. Check whether this subnet does not collide with any other subnet in the headquarters or in the filials. If it does, specify a free subnet.

Figure 21.59 The Paris filial office — VPN server configuration

For a detailed description on the VPN server configuration, refer to chapter 21.1.

349

Page 349
Image 349
Kerio Tech Firewall6 manual 349, The Paris filial office VPN server configuration