SlideShare a Scribd company logo
1 of 30
Download to read offline
OpenVPN with
Mikrotik RouterBOARD
Anthony, Duong Nguyen
Sales Director
Mobile: +84 9 7117 5115 – Email: duongnt@adtek.vn
About Us
Our Company
 Company Name: AD.TEK Joint Stock Company
 Brand name: Advanced Networks Technology
 Head quarter: No.9 Building 10, Lane 95 Chua Boc st., Dong Da dist., Hanoi
 Founded: November 2010
 Resources: 30+ employees with 10+ Technical engineers
 Business: Datacenter and Enterprise Network solutions and products distribution
 Contact: sales@adtek.vn www.adtek.vn
Hanoi Ho Chi Minh City Nha Trang City
45/140 Khuat Duy Tien st.
Thanh Xuan, Hanoi
Hotline: +84 98 672 8080
26F/11 Le Quoc Hung st.
Ward 12, Dist. 4, HCMC.
Hotline: +84 98 652 8080
25 Nguyen Van Bay st.
Phuoc Long, Nha Trang
Hotline: +84 97 235 8080
Our Solutions
 DataCenter: Cable Routing & Pathway system, Structured Cabling System,
Network infrastructure, Network Routing & Switching, Cloud Storage, DCIM,
UPS, Rack & Cabinet
 Enterprise: Structured Cabling system, Routing & Switching, Server & Storage,
Security, Wireless Solution, Video Surveillance, UPS, Rack & Cabinet
 Wireless: Carrier grade Wireless PTP, PMP, Wifi Access Point, Hotspot & Billing
solutions
Our Vertical Market
Healthcare Education Technology Finance Gov./Defense
Our Partners
OpenVPN with Mikrotik RouterOS
Challenges
 Corporate with Head Quarter and multiple branch/offices need to sharing
data between sites
 Corporate with mobile users working out of office and connect to
Private/Local Applications system
 Central managed for IT networking equipments/devices from HQ.
 Over budget for leasedline/MPLS VPN from ISP.
Prerequisites
 Equipments
 HQ networks (LAN, Servers) and Mikrotik Gateway router
 Branch networks with Mikrotik Gateway router
 Technical skill
 Networking basic: TCP/IP, NAT, IPSec, VPN, SSL knowledge based
 RouterOS features, Webfig/Winbox, RouterOS CLI
What is OpenVPN?
 Open Source software application implements VPN (virtual private network)
for creating secure point-to-point or site-to-site connection.
 Written by Jame Yonan and published under GNU General Public License (GPL)
 Support routed or bridged mode and remote access topology
 Used custom security protocol utilized SSL/TSL for key exchange
 Allow peers to authenticate each other using pre-shared secret key,
certificates or username/password.
 Uses the OpenSSL encryption library, as well as the SSLv3/TLSv1 protocol, and
contains many security and control features.
 Has been ported and embedded to several systems like DD-WRT (GNU/Linux-
based firmware for wireless routers and access points), Mikrotik RouterOS,
SoftEther VPN,…
Architecture
 Encryption
 OpenVPN uses the OpenSSL library to
provide encryption of both the data and
control channels. It lets OpenSSL do all
the encryption and authentication work,
allowing OpenVPN to use all the ciphers
available in the OpenSSL package
 Can support the HMAC (Hash-based
message authentication code) packet
authentication feature to add an
additional layer of security to the
connection
 Also support hardware acceleration to
get better encryption performance
 Authentication
 Support pre-shared keys, certificate-
based, and username/password-based
authentication
 Security
 256 bits encryption through OpenSSL
library
 Custom protocol based on SSL and TSL
support IKE, IPSec, L2TP or PPTP.
 Networking
 Support over both UDP or TCP
 Support IPv6 (version 2.3.x)
 Support working through proxy servers
(including HTTP proxy server)
 Support working through NAT
 Support TUN (layer 2) or TAP (layer 3)
interface
 IANA official port: 1194
Mikrotik RouterOS and OpenVPN
 Support
 TCP
 Bridging (TAP interface)
 Routing (TUN interface)
 Certificates
 P2P mode
 Naming Linux/Windows vs.
RouterOS
 TUN - RouterOS: IP
 TAP - RouterOS: ethernet
 Unsupport
 UDP
 LZO Compression
Topology
Topology
How to?
 1. Certificate Generation
 2. Server site VPN gateway setup
 3. Branch site VPN Client setup
 4. Routing & Check connection
Certificates generation
 ssh/telnet to HQ Mikrotik gateway, create your own certificate authority (CA)
named myCA and.
 192.168.1.1 is LAN interface
 export the CA certificate
 Create a private and public key pair for the VPN Server and another key pair
for the VPN Client.
Certificates generation (cont.)
 Sign both public keys with new CA
#/certificate sign OVPNserver ca=myCA name=server
#/certificate sign OVPNbranch ca=myCA name=branch
 Export the VPN branch's private key and public key+certificate files.
 Check your certifcates:
 Check your files:
Certificates generation (cont.)
 Download branch’s certificate files, using sftp/winbox or webfig.
Server site VPN gateway setup
 VPN parameters:
 HQ LAN networks: 192.168.0.0/24; Branch LAN network: 192.168.10.0/24
 VPN Network: 192.168.8.0/24, VPN Gateway: 192.168.8.1
 IP Range for VPN Clients/Branch: 192.168.8.10-192.168.8.20
 Server Certificate = yes
 Auth = SHA1
 Cipher = AES256
 VPN TCP port = 1194
 Client Certificate = Yes
 Mode = IP (Layer 3 routing)
Server site VPN gateway setup (cont.)
 Create the PPP profile and IP address pool
 Check your configuration
Server site VPN gateway setup (cont.)
 Add “branch” user with second factor secret and check your configure
 Replace yourpassword by your own password. This password must match both HQ
and Branch configure.
Server site VPN gateway setup (cont.)
 Create OVPN interface in the HQ-MikrotikGW using certificate, authentication
SHA1, cipher AES256, port 1194, mode IP.
Branch site VPN Client setup
 Import certificate downloaded before to Branch Mikrotik Router using
sftp/webfig/winbox
Branch site VPN Client setup (cont.)
 Import certificates. Using your own password created before for passphrase
 Check your imported certificates:
Branch site VPN Client setup (cont.)
 Add VPN client interface.
 Note:
 Change HQWAN-IP to your HQ Public IP address of HQ-MikrotikGW. If you are using
dynamic IP address, please enable cloud and using domain name.
 Change yourpassword to your own password
Routing & Check connection
 Check VPN Connection.
Routing & Check connection (cont)
Routing & Check connection (cont.)
 On HQ Router:
 On Brand Router:
 Check Routing
Routing & Check connection (cont.)
 From Laptop in Branch, connect to HQ Server
Anthony, Duong Nguyen
Sales Director
Email: duongnt@adtek.vn
Mobile: +84 97 117 5115 / +84 93 448 6969 (Whatsapp/Zalo/Vibers)
Skype: duongnt37
ADVANCED NETWORKS TECHNOLOGY – AD.TEK JSC
Email: sales@adtek.vn Website: http://www.adtek.vn
Hanoi Ho Chi Minh City Nha Trang City
45/140 Khuat Duy Tien st.,
Thanh Xuan dist., Hanoi
Hotline: +84 98 672 8080
26F/11 Le Quoc Hung st.,
Ward 12, District 4, HCMC
Hotline: +84 98 652 8080
25 Nguyen Van Bay st.,
Phuoc Long, Nha Trang City
Hotline: +84 97 235 8080

More Related Content

Similar to presentation_4102_1493726768.pdf

Ip tunnelling and_vpn
Ip tunnelling and_vpnIp tunnelling and_vpn
Ip tunnelling and_vpnRajesh Porwal
 
VPN (virtual private network)
VPN (virtual private network) VPN (virtual private network)
VPN (virtual private network) Netwax Lab
 
Best practices for using VPNs for easy network-to-network protection
Best practices for using VPNs for easy network-to-network protectionBest practices for using VPNs for easy network-to-network protection
Best practices for using VPNs for easy network-to-network protectionWestermo Network Technologies
 
Site to-multi site open vpn solution with mysql db
Site to-multi site open vpn solution with mysql dbSite to-multi site open vpn solution with mysql db
Site to-multi site open vpn solution with mysql dbChanaka Lasantha
 
Implementing 802.1x Authentication
Implementing 802.1x AuthenticationImplementing 802.1x Authentication
Implementing 802.1x Authenticationdkaya
 
Site to-multi site open vpn solution. with active directory auth
Site to-multi site open vpn solution. with active directory authSite to-multi site open vpn solution. with active directory auth
Site to-multi site open vpn solution. with active directory authChanaka Lasantha
 
VPN presentation
VPN presentationVPN presentation
VPN presentationRiazehri
 
Site to-multi site open vpn solution-latest
Site to-multi site open vpn solution-latestSite to-multi site open vpn solution-latest
Site to-multi site open vpn solution-latestChanaka Lasantha
 
Remote access connection
Remote access connection Remote access connection
Remote access connection Ah Fawad Saiq
 
2014 innovaphone different protocols for different things
2014 innovaphone different protocols for different things2014 innovaphone different protocols for different things
2014 innovaphone different protocols for different thingsVOIP2DAY
 
What Technology Lies Behind VPN
What Technology Lies Behind VPNWhat Technology Lies Behind VPN
What Technology Lies Behind VPNSovello Hildebrand
 
The 5 elements of IoT security
The 5 elements of IoT securityThe 5 elements of IoT security
The 5 elements of IoT securityJulien Vermillard
 
Certificate Based VPN Remote Access - 1. OpenCA Workshop 2004 / OpenXPKI
Certificate Based VPN Remote Access - 1. OpenCA Workshop 2004 / OpenXPKICertificate Based VPN Remote Access - 1. OpenCA Workshop 2004 / OpenXPKI
Certificate Based VPN Remote Access - 1. OpenCA Workshop 2004 / OpenXPKIIves Laaf
 
Virtual Private Network (VPN).
Virtual Private Network (VPN).Virtual Private Network (VPN).
Virtual Private Network (VPN).Debasis Chowdhury
 
VMworld 2013: vCloud Hybrid Service Jump Start Part Two of Five: vCloud Hybri...
VMworld 2013: vCloud Hybrid Service Jump Start Part Two of Five: vCloud Hybri...VMworld 2013: vCloud Hybrid Service Jump Start Part Two of Five: vCloud Hybri...
VMworld 2013: vCloud Hybrid Service Jump Start Part Two of Five: vCloud Hybri...VMworld
 

Similar to presentation_4102_1493726768.pdf (20)

RemoteAdmin.pptx
RemoteAdmin.pptxRemoteAdmin.pptx
RemoteAdmin.pptx
 
Ip tunneling and vpns
Ip tunneling and vpnsIp tunneling and vpns
Ip tunneling and vpns
 
Ip tunnelling and_vpn
Ip tunnelling and_vpnIp tunnelling and_vpn
Ip tunnelling and_vpn
 
VPN (virtual private network)
VPN (virtual private network) VPN (virtual private network)
VPN (virtual private network)
 
V P N
V P NV P N
V P N
 
Best practices for using VPNs for easy network-to-network protection
Best practices for using VPNs for easy network-to-network protectionBest practices for using VPNs for easy network-to-network protection
Best practices for using VPNs for easy network-to-network protection
 
Site to-multi site open vpn solution with mysql db
Site to-multi site open vpn solution with mysql dbSite to-multi site open vpn solution with mysql db
Site to-multi site open vpn solution with mysql db
 
Implementing 802.1x Authentication
Implementing 802.1x AuthenticationImplementing 802.1x Authentication
Implementing 802.1x Authentication
 
Site to-multi site open vpn solution. with active directory auth
Site to-multi site open vpn solution. with active directory authSite to-multi site open vpn solution. with active directory auth
Site to-multi site open vpn solution. with active directory auth
 
VPN presentation
VPN presentationVPN presentation
VPN presentation
 
Site to-multi site open vpn solution-latest
Site to-multi site open vpn solution-latestSite to-multi site open vpn solution-latest
Site to-multi site open vpn solution-latest
 
Remote access connection
Remote access connection Remote access connection
Remote access connection
 
MTCNA Show.pptx
MTCNA Show.pptxMTCNA Show.pptx
MTCNA Show.pptx
 
2014 innovaphone different protocols for different things
2014 innovaphone different protocols for different things2014 innovaphone different protocols for different things
2014 innovaphone different protocols for different things
 
Profile_Prateek
Profile_PrateekProfile_Prateek
Profile_Prateek
 
What Technology Lies Behind VPN
What Technology Lies Behind VPNWhat Technology Lies Behind VPN
What Technology Lies Behind VPN
 
The 5 elements of IoT security
The 5 elements of IoT securityThe 5 elements of IoT security
The 5 elements of IoT security
 
Certificate Based VPN Remote Access - 1. OpenCA Workshop 2004 / OpenXPKI
Certificate Based VPN Remote Access - 1. OpenCA Workshop 2004 / OpenXPKICertificate Based VPN Remote Access - 1. OpenCA Workshop 2004 / OpenXPKI
Certificate Based VPN Remote Access - 1. OpenCA Workshop 2004 / OpenXPKI
 
Virtual Private Network (VPN).
Virtual Private Network (VPN).Virtual Private Network (VPN).
Virtual Private Network (VPN).
 
VMworld 2013: vCloud Hybrid Service Jump Start Part Two of Five: vCloud Hybri...
VMworld 2013: vCloud Hybrid Service Jump Start Part Two of Five: vCloud Hybri...VMworld 2013: vCloud Hybrid Service Jump Start Part Two of Five: vCloud Hybri...
VMworld 2013: vCloud Hybrid Service Jump Start Part Two of Five: vCloud Hybri...
 

Recently uploaded

TEST BANK For Evidence-Based Practice for Nurses Appraisal and Application of...
TEST BANK For Evidence-Based Practice for Nurses Appraisal and Application of...TEST BANK For Evidence-Based Practice for Nurses Appraisal and Application of...
TEST BANK For Evidence-Based Practice for Nurses Appraisal and Application of...robinsonayot
 
Experience Certificate - Marketing Analyst-Soham Mondal.pdf
Experience Certificate - Marketing Analyst-Soham Mondal.pdfExperience Certificate - Marketing Analyst-Soham Mondal.pdf
Experience Certificate - Marketing Analyst-Soham Mondal.pdfSoham Mondal
 
VIP Call Girls Service Saharanpur Aishwarya 8250192130 Independent Escort Ser...
VIP Call Girls Service Saharanpur Aishwarya 8250192130 Independent Escort Ser...VIP Call Girls Service Saharanpur Aishwarya 8250192130 Independent Escort Ser...
VIP Call Girls Service Saharanpur Aishwarya 8250192130 Independent Escort Ser...Suhani Kapoor
 
VIP Call Girls in Jamshedpur Aarohi 8250192130 Independent Escort Service Jam...
VIP Call Girls in Jamshedpur Aarohi 8250192130 Independent Escort Service Jam...VIP Call Girls in Jamshedpur Aarohi 8250192130 Independent Escort Service Jam...
VIP Call Girls in Jamshedpur Aarohi 8250192130 Independent Escort Service Jam...Suhani Kapoor
 
VIP Call Girl Bhiwandi Aashi 8250192130 Independent Escort Service Bhiwandi
VIP Call Girl Bhiwandi Aashi 8250192130 Independent Escort Service BhiwandiVIP Call Girl Bhiwandi Aashi 8250192130 Independent Escort Service Bhiwandi
VIP Call Girl Bhiwandi Aashi 8250192130 Independent Escort Service BhiwandiSuhani Kapoor
 
CFO_SB_Career History_Multi Sector Experience
CFO_SB_Career History_Multi Sector ExperienceCFO_SB_Career History_Multi Sector Experience
CFO_SB_Career History_Multi Sector ExperienceSanjay Bokadia
 
VIP Call Girls Service Cuttack Aishwarya 8250192130 Independent Escort Servic...
VIP Call Girls Service Cuttack Aishwarya 8250192130 Independent Escort Servic...VIP Call Girls Service Cuttack Aishwarya 8250192130 Independent Escort Servic...
VIP Call Girls Service Cuttack Aishwarya 8250192130 Independent Escort Servic...Suhani Kapoor
 
Zeeman Effect normal and Anomalous zeeman effect
Zeeman Effect normal and Anomalous zeeman effectZeeman Effect normal and Anomalous zeeman effect
Zeeman Effect normal and Anomalous zeeman effectPriyanshuRawat56
 
VIP Russian Call Girls in Amravati Deepika 8250192130 Independent Escort Serv...
VIP Russian Call Girls in Amravati Deepika 8250192130 Independent Escort Serv...VIP Russian Call Girls in Amravati Deepika 8250192130 Independent Escort Serv...
VIP Russian Call Girls in Amravati Deepika 8250192130 Independent Escort Serv...Suhani Kapoor
 
Booking open Available Pune Call Girls Ambegaon Khurd 6297143586 Call Hot In...
Booking open Available Pune Call Girls Ambegaon Khurd  6297143586 Call Hot In...Booking open Available Pune Call Girls Ambegaon Khurd  6297143586 Call Hot In...
Booking open Available Pune Call Girls Ambegaon Khurd 6297143586 Call Hot In...Call Girls in Nagpur High Profile
 
内布拉斯加大学林肯分校毕业证录取书( 退学 )学位证书硕士
内布拉斯加大学林肯分校毕业证录取书( 退学 )学位证书硕士内布拉斯加大学林肯分校毕业证录取书( 退学 )学位证书硕士
内布拉斯加大学林肯分校毕业证录取书( 退学 )学位证书硕士obuhobo
 
VIP High Profile Call Girls Jamshedpur Aarushi 8250192130 Independent Escort ...
VIP High Profile Call Girls Jamshedpur Aarushi 8250192130 Independent Escort ...VIP High Profile Call Girls Jamshedpur Aarushi 8250192130 Independent Escort ...
VIP High Profile Call Girls Jamshedpur Aarushi 8250192130 Independent Escort ...Suhani Kapoor
 
女王大学硕士毕业证成绩单(加急办理)认证海外毕业证
女王大学硕士毕业证成绩单(加急办理)认证海外毕业证女王大学硕士毕业证成绩单(加急办理)认证海外毕业证
女王大学硕士毕业证成绩单(加急办理)认证海外毕业证obuhobo
 
CALL ON ➥8923113531 🔝Call Girls Nishatganj Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Nishatganj Lucknow best sexual serviceCALL ON ➥8923113531 🔝Call Girls Nishatganj Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Nishatganj Lucknow best sexual serviceanilsa9823
 
Internshala Student Partner 6.0 Jadavpur University Certificate
Internshala Student Partner 6.0 Jadavpur University CertificateInternshala Student Partner 6.0 Jadavpur University Certificate
Internshala Student Partner 6.0 Jadavpur University CertificateSoham Mondal
 
VIP Call Girl Cuttack Aashi 8250192130 Independent Escort Service Cuttack
VIP Call Girl Cuttack Aashi 8250192130 Independent Escort Service CuttackVIP Call Girl Cuttack Aashi 8250192130 Independent Escort Service Cuttack
VIP Call Girl Cuttack Aashi 8250192130 Independent Escort Service CuttackSuhani Kapoor
 
PM Job Search Council Info Session - PMI Silver Spring Chapter
PM Job Search Council Info Session - PMI Silver Spring ChapterPM Job Search Council Info Session - PMI Silver Spring Chapter
PM Job Search Council Info Session - PMI Silver Spring ChapterHector Del Castillo, CPM, CPMM
 
VIP Russian Call Girls in Bhilai Deepika 8250192130 Independent Escort Servic...
VIP Russian Call Girls in Bhilai Deepika 8250192130 Independent Escort Servic...VIP Russian Call Girls in Bhilai Deepika 8250192130 Independent Escort Servic...
VIP Russian Call Girls in Bhilai Deepika 8250192130 Independent Escort Servic...Suhani Kapoor
 
Call Girls Alandi Road Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Alandi Road Call Me 7737669865 Budget Friendly No Advance BookingCall Girls Alandi Road Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Alandi Road Call Me 7737669865 Budget Friendly No Advance Bookingroncy bisnoi
 

Recently uploaded (20)

TEST BANK For Evidence-Based Practice for Nurses Appraisal and Application of...
TEST BANK For Evidence-Based Practice for Nurses Appraisal and Application of...TEST BANK For Evidence-Based Practice for Nurses Appraisal and Application of...
TEST BANK For Evidence-Based Practice for Nurses Appraisal and Application of...
 
Experience Certificate - Marketing Analyst-Soham Mondal.pdf
Experience Certificate - Marketing Analyst-Soham Mondal.pdfExperience Certificate - Marketing Analyst-Soham Mondal.pdf
Experience Certificate - Marketing Analyst-Soham Mondal.pdf
 
VIP Call Girls Service Saharanpur Aishwarya 8250192130 Independent Escort Ser...
VIP Call Girls Service Saharanpur Aishwarya 8250192130 Independent Escort Ser...VIP Call Girls Service Saharanpur Aishwarya 8250192130 Independent Escort Ser...
VIP Call Girls Service Saharanpur Aishwarya 8250192130 Independent Escort Ser...
 
VIP Call Girls in Jamshedpur Aarohi 8250192130 Independent Escort Service Jam...
VIP Call Girls in Jamshedpur Aarohi 8250192130 Independent Escort Service Jam...VIP Call Girls in Jamshedpur Aarohi 8250192130 Independent Escort Service Jam...
VIP Call Girls in Jamshedpur Aarohi 8250192130 Independent Escort Service Jam...
 
VIP Call Girl Bhiwandi Aashi 8250192130 Independent Escort Service Bhiwandi
VIP Call Girl Bhiwandi Aashi 8250192130 Independent Escort Service BhiwandiVIP Call Girl Bhiwandi Aashi 8250192130 Independent Escort Service Bhiwandi
VIP Call Girl Bhiwandi Aashi 8250192130 Independent Escort Service Bhiwandi
 
CFO_SB_Career History_Multi Sector Experience
CFO_SB_Career History_Multi Sector ExperienceCFO_SB_Career History_Multi Sector Experience
CFO_SB_Career History_Multi Sector Experience
 
Call Girls In Prashant Vihar꧁❤ 🔝 9953056974🔝❤꧂ Escort ServiCe
Call Girls In Prashant Vihar꧁❤ 🔝 9953056974🔝❤꧂ Escort ServiCeCall Girls In Prashant Vihar꧁❤ 🔝 9953056974🔝❤꧂ Escort ServiCe
Call Girls In Prashant Vihar꧁❤ 🔝 9953056974🔝❤꧂ Escort ServiCe
 
VIP Call Girls Service Cuttack Aishwarya 8250192130 Independent Escort Servic...
VIP Call Girls Service Cuttack Aishwarya 8250192130 Independent Escort Servic...VIP Call Girls Service Cuttack Aishwarya 8250192130 Independent Escort Servic...
VIP Call Girls Service Cuttack Aishwarya 8250192130 Independent Escort Servic...
 
Zeeman Effect normal and Anomalous zeeman effect
Zeeman Effect normal and Anomalous zeeman effectZeeman Effect normal and Anomalous zeeman effect
Zeeman Effect normal and Anomalous zeeman effect
 
VIP Russian Call Girls in Amravati Deepika 8250192130 Independent Escort Serv...
VIP Russian Call Girls in Amravati Deepika 8250192130 Independent Escort Serv...VIP Russian Call Girls in Amravati Deepika 8250192130 Independent Escort Serv...
VIP Russian Call Girls in Amravati Deepika 8250192130 Independent Escort Serv...
 
Booking open Available Pune Call Girls Ambegaon Khurd 6297143586 Call Hot In...
Booking open Available Pune Call Girls Ambegaon Khurd  6297143586 Call Hot In...Booking open Available Pune Call Girls Ambegaon Khurd  6297143586 Call Hot In...
Booking open Available Pune Call Girls Ambegaon Khurd 6297143586 Call Hot In...
 
内布拉斯加大学林肯分校毕业证录取书( 退学 )学位证书硕士
内布拉斯加大学林肯分校毕业证录取书( 退学 )学位证书硕士内布拉斯加大学林肯分校毕业证录取书( 退学 )学位证书硕士
内布拉斯加大学林肯分校毕业证录取书( 退学 )学位证书硕士
 
VIP High Profile Call Girls Jamshedpur Aarushi 8250192130 Independent Escort ...
VIP High Profile Call Girls Jamshedpur Aarushi 8250192130 Independent Escort ...VIP High Profile Call Girls Jamshedpur Aarushi 8250192130 Independent Escort ...
VIP High Profile Call Girls Jamshedpur Aarushi 8250192130 Independent Escort ...
 
女王大学硕士毕业证成绩单(加急办理)认证海外毕业证
女王大学硕士毕业证成绩单(加急办理)认证海外毕业证女王大学硕士毕业证成绩单(加急办理)认证海外毕业证
女王大学硕士毕业证成绩单(加急办理)认证海外毕业证
 
CALL ON ➥8923113531 🔝Call Girls Nishatganj Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Nishatganj Lucknow best sexual serviceCALL ON ➥8923113531 🔝Call Girls Nishatganj Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Nishatganj Lucknow best sexual service
 
Internshala Student Partner 6.0 Jadavpur University Certificate
Internshala Student Partner 6.0 Jadavpur University CertificateInternshala Student Partner 6.0 Jadavpur University Certificate
Internshala Student Partner 6.0 Jadavpur University Certificate
 
VIP Call Girl Cuttack Aashi 8250192130 Independent Escort Service Cuttack
VIP Call Girl Cuttack Aashi 8250192130 Independent Escort Service CuttackVIP Call Girl Cuttack Aashi 8250192130 Independent Escort Service Cuttack
VIP Call Girl Cuttack Aashi 8250192130 Independent Escort Service Cuttack
 
PM Job Search Council Info Session - PMI Silver Spring Chapter
PM Job Search Council Info Session - PMI Silver Spring ChapterPM Job Search Council Info Session - PMI Silver Spring Chapter
PM Job Search Council Info Session - PMI Silver Spring Chapter
 
VIP Russian Call Girls in Bhilai Deepika 8250192130 Independent Escort Servic...
VIP Russian Call Girls in Bhilai Deepika 8250192130 Independent Escort Servic...VIP Russian Call Girls in Bhilai Deepika 8250192130 Independent Escort Servic...
VIP Russian Call Girls in Bhilai Deepika 8250192130 Independent Escort Servic...
 
Call Girls Alandi Road Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Alandi Road Call Me 7737669865 Budget Friendly No Advance BookingCall Girls Alandi Road Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Alandi Road Call Me 7737669865 Budget Friendly No Advance Booking
 

presentation_4102_1493726768.pdf

  • 1. OpenVPN with Mikrotik RouterBOARD Anthony, Duong Nguyen Sales Director Mobile: +84 9 7117 5115 – Email: duongnt@adtek.vn
  • 3. Our Company  Company Name: AD.TEK Joint Stock Company  Brand name: Advanced Networks Technology  Head quarter: No.9 Building 10, Lane 95 Chua Boc st., Dong Da dist., Hanoi  Founded: November 2010  Resources: 30+ employees with 10+ Technical engineers  Business: Datacenter and Enterprise Network solutions and products distribution  Contact: sales@adtek.vn www.adtek.vn Hanoi Ho Chi Minh City Nha Trang City 45/140 Khuat Duy Tien st. Thanh Xuan, Hanoi Hotline: +84 98 672 8080 26F/11 Le Quoc Hung st. Ward 12, Dist. 4, HCMC. Hotline: +84 98 652 8080 25 Nguyen Van Bay st. Phuoc Long, Nha Trang Hotline: +84 97 235 8080
  • 4. Our Solutions  DataCenter: Cable Routing & Pathway system, Structured Cabling System, Network infrastructure, Network Routing & Switching, Cloud Storage, DCIM, UPS, Rack & Cabinet  Enterprise: Structured Cabling system, Routing & Switching, Server & Storage, Security, Wireless Solution, Video Surveillance, UPS, Rack & Cabinet  Wireless: Carrier grade Wireless PTP, PMP, Wifi Access Point, Hotspot & Billing solutions
  • 5. Our Vertical Market Healthcare Education Technology Finance Gov./Defense
  • 8. Challenges  Corporate with Head Quarter and multiple branch/offices need to sharing data between sites  Corporate with mobile users working out of office and connect to Private/Local Applications system  Central managed for IT networking equipments/devices from HQ.  Over budget for leasedline/MPLS VPN from ISP.
  • 9. Prerequisites  Equipments  HQ networks (LAN, Servers) and Mikrotik Gateway router  Branch networks with Mikrotik Gateway router  Technical skill  Networking basic: TCP/IP, NAT, IPSec, VPN, SSL knowledge based  RouterOS features, Webfig/Winbox, RouterOS CLI
  • 10. What is OpenVPN?  Open Source software application implements VPN (virtual private network) for creating secure point-to-point or site-to-site connection.  Written by Jame Yonan and published under GNU General Public License (GPL)  Support routed or bridged mode and remote access topology  Used custom security protocol utilized SSL/TSL for key exchange  Allow peers to authenticate each other using pre-shared secret key, certificates or username/password.  Uses the OpenSSL encryption library, as well as the SSLv3/TLSv1 protocol, and contains many security and control features.  Has been ported and embedded to several systems like DD-WRT (GNU/Linux- based firmware for wireless routers and access points), Mikrotik RouterOS, SoftEther VPN,…
  • 11. Architecture  Encryption  OpenVPN uses the OpenSSL library to provide encryption of both the data and control channels. It lets OpenSSL do all the encryption and authentication work, allowing OpenVPN to use all the ciphers available in the OpenSSL package  Can support the HMAC (Hash-based message authentication code) packet authentication feature to add an additional layer of security to the connection  Also support hardware acceleration to get better encryption performance  Authentication  Support pre-shared keys, certificate- based, and username/password-based authentication  Security  256 bits encryption through OpenSSL library  Custom protocol based on SSL and TSL support IKE, IPSec, L2TP or PPTP.  Networking  Support over both UDP or TCP  Support IPv6 (version 2.3.x)  Support working through proxy servers (including HTTP proxy server)  Support working through NAT  Support TUN (layer 2) or TAP (layer 3) interface  IANA official port: 1194
  • 12. Mikrotik RouterOS and OpenVPN  Support  TCP  Bridging (TAP interface)  Routing (TUN interface)  Certificates  P2P mode  Naming Linux/Windows vs. RouterOS  TUN - RouterOS: IP  TAP - RouterOS: ethernet  Unsupport  UDP  LZO Compression
  • 15. How to?  1. Certificate Generation  2. Server site VPN gateway setup  3. Branch site VPN Client setup  4. Routing & Check connection
  • 16. Certificates generation  ssh/telnet to HQ Mikrotik gateway, create your own certificate authority (CA) named myCA and.  192.168.1.1 is LAN interface  export the CA certificate  Create a private and public key pair for the VPN Server and another key pair for the VPN Client.
  • 17. Certificates generation (cont.)  Sign both public keys with new CA #/certificate sign OVPNserver ca=myCA name=server #/certificate sign OVPNbranch ca=myCA name=branch  Export the VPN branch's private key and public key+certificate files.  Check your certifcates:  Check your files:
  • 18. Certificates generation (cont.)  Download branch’s certificate files, using sftp/winbox or webfig.
  • 19. Server site VPN gateway setup  VPN parameters:  HQ LAN networks: 192.168.0.0/24; Branch LAN network: 192.168.10.0/24  VPN Network: 192.168.8.0/24, VPN Gateway: 192.168.8.1  IP Range for VPN Clients/Branch: 192.168.8.10-192.168.8.20  Server Certificate = yes  Auth = SHA1  Cipher = AES256  VPN TCP port = 1194  Client Certificate = Yes  Mode = IP (Layer 3 routing)
  • 20. Server site VPN gateway setup (cont.)  Create the PPP profile and IP address pool  Check your configuration
  • 21. Server site VPN gateway setup (cont.)  Add “branch” user with second factor secret and check your configure  Replace yourpassword by your own password. This password must match both HQ and Branch configure.
  • 22. Server site VPN gateway setup (cont.)  Create OVPN interface in the HQ-MikrotikGW using certificate, authentication SHA1, cipher AES256, port 1194, mode IP.
  • 23. Branch site VPN Client setup  Import certificate downloaded before to Branch Mikrotik Router using sftp/webfig/winbox
  • 24. Branch site VPN Client setup (cont.)  Import certificates. Using your own password created before for passphrase  Check your imported certificates:
  • 25. Branch site VPN Client setup (cont.)  Add VPN client interface.  Note:  Change HQWAN-IP to your HQ Public IP address of HQ-MikrotikGW. If you are using dynamic IP address, please enable cloud and using domain name.  Change yourpassword to your own password
  • 26. Routing & Check connection  Check VPN Connection.
  • 27. Routing & Check connection (cont)
  • 28. Routing & Check connection (cont.)  On HQ Router:  On Brand Router:  Check Routing
  • 29. Routing & Check connection (cont.)  From Laptop in Branch, connect to HQ Server
  • 30. Anthony, Duong Nguyen Sales Director Email: duongnt@adtek.vn Mobile: +84 97 117 5115 / +84 93 448 6969 (Whatsapp/Zalo/Vibers) Skype: duongnt37 ADVANCED NETWORKS TECHNOLOGY – AD.TEK JSC Email: sales@adtek.vn Website: http://www.adtek.vn Hanoi Ho Chi Minh City Nha Trang City 45/140 Khuat Duy Tien st., Thanh Xuan dist., Hanoi Hotline: +84 98 672 8080 26F/11 Le Quoc Hung st., Ward 12, District 4, HCMC Hotline: +84 98 652 8080 25 Nguyen Van Bay st., Phuoc Long, Nha Trang City Hotline: +84 97 235 8080