110
User Manual ENGLISH
WHG-Series Wireless WLAN Controller
Copyright © 2017, 4ipnet, Inc. All rights reserved. All other trademarks mentioned are the property of their respective owners.
11
How to enable VPN feature
Multiple types of VPN are available on the system: Remote VPN, and Site-to-Site VPN. For Remote VPN,
the system allows the VPN tunnel between a remote client and the system to encrypt the data
transmission via PPTP or IKEv2. For the Site-to-Site VPN, an IPSec tunnel can be used to connect to other
IPSec capable device over the Internet.
11.1
Remote VPN PPTP
WLAN controller supports Remote VPN for user login to system from a remote area. After the user is
logged in to system from the outside network of WAN, it will appear to the user that the login to WLAN
controller is under the service zone locally. Policy can also be applied and users are controlled by system
to access the network.
All settings are similar to the settings in a Service Zone. Remote VPN can also be setup with a SIP WAN
Interface, Authentication Options, Group Permission, and Applied Policy.
Function: to enable or disable the Remote VPN PPTP feature in the system
Allocate IP Address from: the IP range for VPN clients. Default is 172.29.0.1/24
WISPr: to include some attributes in RADIUS protocol when integrate with RADIUS authentication server
Authentication Options: Databases for IKEv2 are built-in LOCAL database, external RADIUS authentication
server, NTDomain, LDAP, and POP3 server
Note
: PPTP, IKEv2 and Site-to-site VPN can work respectively
Note
: the Remote VPN clients can be applied by different user policies at the page of
Main › Users › Groups › Configuration
11.2
Remote VPN IKEv2
Currently, some Operating Systems have decided not to support the PPTP connection such as iOS10,
macOS Sierra or newer OS. Therefore, for maintaining the remote VPN feature, IKEv2 solution,
a modern
protocol developed by Microsoft and Cisco, was chosen as a default VPN type in OS X 10.11 (El Capitan)
and Windows since 7. It supports strong encryption, auto reconnection on network change, easy
configuration and more.
Function: to enable or disable the Remote VPN IKEv2 feature in the system
Allocate IP Address from: the IP range for VPN clients. Default is 172.16.0.1/24
Certificate: to
assign the legal certificate for IPSec tunnel used
WISPr: to include some attributes in RADIUS protocol when integrate with RADIUS authentication server
Authentication Options: Databases for IKEv2 are only built-in LOCAL database and external RADIUS
authentication server.
Note
: PPTP, IKEv2 and Site-to-site VPN can work respectively
Note
: the Remote VPN clients can be applied by different user policies at the page of
Main › Users › Groups › Configuration