05.08.2013 Views

OpenVPN Access Server System Administrator Guide

OpenVPN Access Server System Administrator Guide

OpenVPN Access Server System Administrator Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Note that to avoid security warnings with Web browsers, the server certificate must have a Subject<br />

Name with a “Common Name” field equal to the FQDN or IP address that clients will use to access<br />

the server. That is the purpose of specifying the FQDN in the “openssl req” step above.<br />

5.5 <strong>Server</strong>-locked Profile<br />

The server-locked profile allows any VPN User the ability to connect with the profile. This was<br />

created for a one size fits all solution. This profile is now offered to all users by default.<br />

6 Additional Information on RADIUS Support<br />

As of <strong>OpenVPN</strong> <strong>Access</strong> <strong>Server</strong> version 1.1 the RADIUS support includes support for RFC2865<br />

and RFC2866. Please note that extensions beyond the previous mentioned RFC‟s, such as<br />

Microsoft extension MS-CHAP V2 are not supported at this time. This should be kept in mind<br />

when configuring a RADIUS server to interoperate with <strong>OpenVPN</strong> <strong>Access</strong> Sever.<br />

6.1 RADIUS Authentication Attributes<br />

As of <strong>OpenVPN</strong> <strong>Access</strong> <strong>Server</strong> version 1.1 the RADIUS support includes the following<br />

Authentication Attributes as prescribed by RFC2865 and RFC2866:<br />

1. User-Name<br />

2. User-Password<br />

3. NAS-Identifier<br />

4. NAS-Port-Type<br />

5. NAS-Port<br />

6. NAS-IP-Address<br />

7. Service-Type<br />

8. Framed-Protocol<br />

9. Framed-IP-Address<br />

10. Framed-IP-Netmask<br />

6.2 RADIUS Accounting Attributes<br />

As of <strong>OpenVPN</strong> <strong>Access</strong> <strong>Server</strong> version 1.1 the RADIUS support includes the following<br />

Accounting Attributes as prescribed by the RFC2865 and RFC2866:<br />

1. Acct-Status-Type<br />

2. Acct-Session-Id<br />

3. Acct-Session-Time<br />

4. Acct-Terminate-Cause<br />

5. Acct-Input-Octets<br />

6. Acct-Output-Octets<br />

<strong>OpenVPN</strong> <strong>Access</strong> <strong>Server</strong> <strong>System</strong> <strong>Administrator</strong> <strong>Guide</strong><br />

51

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!