Configuring Kerio VPN Server
Kerio VPNVirtual private network - A network that enables users connect securely to a private network over the Internet. Server offers clients such desktops, notebooks, mobile devices, etc. a secure way to connect to the network.
NOTE
You must enable communication through VPN in Traffic Rules before start configuring the Kerio VPN Server. For more information refer to Configuring traffic rules.
To configure Kerio VPN Server:
Configuring Interface
To configure Interface:
- In the administration interface, go to Interfaces.
- Double-click VPN Server.
- In the VPN Server Properties dialog, check Enable Kerio VPN Server.
- On tab Kerio VPN, select a valid certificate.
- The port
4090
is set as default. Both TCPTransmission Control Protocol - ensures packet transmission. and UDPUser Datagram Protocol - ensures packet transmission. protocols are used.
NOTES
Do not switch to another port without a proper reason.
If it is not possible to run the VPN Server on the specified port, the error is reported in the Error log.
- To specify a VPN route manually, read section Configuring routing.
- Kerio VPN Server directs the traffic from VPN clients in two ways:
- Only traffic which ends in the Kerio Control network goes through the firewall — default mode. This type of connection is called split tunneling.
- All traffic goes through the firewall — select VPN clients access the Internet through the VPN.
- Verify that your default Internet access (NATNetwork address translation - A method that remaps IP addresses by changing network address information.) rule includes the VPN clients item.
- Save the settings.
Configuring routing
By default, routes to all local subnets at the VPN Server's side are defined. Other networks to which a VPN route will be set for the client can be specified:
- In the administration interface, go to Interfaces.
- Double-click the VPN Server.
- On tab Kerio VPN, click Custom Routes.
- Click Add.
- In the Add Route dialog box, define a network, mask and description. In case of any collisions, custom routes are used instead.
- Save the settings.
NOTE
Use the 255.255.255.255 network mask to define a route to a specific host. It can be helpful when adding a route to a host in the demilitarized zone at the VPN Server's side.
Configuring DNS
Kerio VPN Server needs a DNSDomain Name System - A database enables the translation of hostnames to IP addresses and provides other domain related information. Server to be used. There are two possible configuration options:
Using the Kerio Control DNS server
To use the DNS server in Kerio Control for Kerio Control VPN Clients:
- In the administration interface, go to Interfaces.
- Double-click VPN Server.
- On the DNS tab, select Use Kerio Control as DNS server.
- Select Automatically select the domain suffix.
- Click OK.
Kerio Control uses its own DNS server for Kerio Control VPN Clients and uses the domain suffix specific for the Kerio Control network.
Using external DNS servers
To assign specific DNS servers to Kerio Control VPN Clients:
- In the administration interface, go to Interfaces.
- Double-click VPN Server.
- On the DNS tab, select Use specific DNS servers.
- In Primary DNS, type a fully qualified domain name.
- (Optional) In Secondary DNS, type a fully qualified domain name of the backup DNS server.
- If you want to use a different domain suffix, select Use specific domain suffix. Then type the domain suffix.
- Click OK.
The DNS servers are assigned to all Kerio Control VPN Clients and the domain suffix is changed.
NOTE
To use WINS to Kerio Control VPN Clients, select the WINS tab in the VPN Server Properties dialog box, and specify the WINS server.
Configuring Kerio Control VPN Clients
The following conditions must be met to enable connection of remote clients to local networks:
- Kerio VPN Client must be installed on remote clients. For more information refer to Installing and configuring Kerio Control VPN Client for users.
- In the Users and Groups > Users section, check a right Users can connect using VPN for your users.
- Connection to the VPN Server from the Internet as well as communication between VPN Clients must be allowed by traffic rules. There is a default traffic policy rule which should be enabled. Otherwise, there is a defined service for Kerio VPN (TCP/UDP 4090) in case you do not have this rule.
NOTE
Kerio Control VPN Clients connected to the firewall are monitored in the Status > VPN Clients section.
Assigning static IP addresses for Kerio Control VPN Clients
For more information refer to Assigning static IP addresses for Kerio Control VPN Clients.