22/07/2014
Matrix Technical Support Mailer – 167
NAVAN CNX200 PPTP VPN with Windows Client
Dear Friends,This mailer helps you in understanding and configuring PPTP VPN of Matrix NAVAN CNX200 with Windows client.
Introduction of VPN:
A virtual private network (VPN) is a private network, which uses the public network (Internet) to connect two computers or two networks or remote offices/users located at different remote sites on the network to share or access data securely, as if they are in the same network
A VPN is composed of two parts: VPN Server and VPN Client There are two common types of VPN:
1. Remote Access VPN 2. Site to Site VPN
A well designed VPN includes data encryption, tunneling, data integration and authentication processes. To perform all these processes, VPN can be created using several security protocols, as below:
1. Internet Protocol Security (IPsec) 2. Layer Two Tunneling Protocol (L2TP) 3. Secure Sockets Layer (SSL)
4. Point-to-Point Tunneling Protocol (PPTP) Introduction of PPTP Protocol:
Point to Point Tunneling Protocol
22/07/2014
PPTP is based on PPP negotiation, authentication and encryption schemes NAVAN supports 10 VPN Connections (as a Server) and 10 VPN Connections(as a Client) for PPTP
In this MTSM NAVAN will work as PPTP server and PC/Laptop with Windows OS will work as PPTP client.
Configuration in NAVAN (PPTP Server): Server signifies that system should work as PPTP server and create the tunnel on request from client
1. Open GUI of NAVAN with the current IP address of NAVAN (Default IP address of LAN and WAN port of NAVAN CNX200 is 192.168.2.56 and
22/07/2014
2. After successful login click on VPN tab.3. Click on PPTP option on the left pane under VPN option and program required parameters
22/07/2014
Assign IP address signifies the range of IP address which should be assigned
to PPTP clients when connected with PPTP VPN tunnel. Make sure that LAN IP and VPN Client IP are in different subnet
Primary and Secondary DNS server signifies that IP address programmed
here should be assigned to PPTP clients to resolve domain name query of internal network hosts
WINS Server signifies that IP address programmed here should be assigned
to PPTP clients to resolve NETBIOS name TCP/IP query from connected PPTP clients of internal network hosts (Admin can program this if any WINS server is available in internal network)
User Authentication Protocol signifies that PPTP server should use here
programmed authentication protocol to authenticate remote devices PPTP clients
1. PAP (Password Authentication Protocol)
2. CHAP (Challenge Handshake Authentication Protocol) (Stronger than PAP)
Disconnect after idle timer signifies that if packets are not sent or received from this tunnel till the expiry of this timer, system should disconnect the tunnel of that PPTP client
22/07/2014
5. Program User name and Password for PPTP member PPTP members signifies that here selected users should be allowed to
connect with system PPTP server
User Name and Password should be defined on server side and same should
be given to clients for connection establishment
Configure the IP address you want to allow access to. It can be: 1. Single IP address
2. IP subnet (Allow access to the entire remote network of the client) 3. None or Road Warrior (If you want to allow access to any IP address) For example, we are setting User Name as test and Password as matrix
22/07/2014
22/07/2014
Configuration in PC/Laptop (PPTP Client):
22/07/2014
2. Click set up a new connection or network option as shown below.3. A new window titled Choose a connection option appears, which asks you to select the type of connection you want to do. Select Connect to a
22/07/2014
4. Select the type of connection to connect to the workplace. Select Use myInternet Connection (VPN) to connect using VPN Connection.
5. In Internet address, enter the internet address to which you wish to connect to; which is actually the Server Address (IP address or domain name of
NAVAN).
In Destination name, enter the desired name of the destination which you want to be displayed as icon of this new VPN connection.
22/07/2014
22/07/2014
7. The VPN Connection is ready to use. The connection usually takes not morethan a minute.
22/07/2014
Windows Client is now connected with NAVAN via PPTP VPN Tunnel and same can be checked in status of NAVAN
Go Status VPN Connections in VPN tab