30.01.2015 Views

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

23.5 Example of <strong>Kerio</strong> VPN configuration: company with a filial office<br />

When the VPN tunnel is created, customize these rules according to the restriction<br />

requirements (see item 6).<br />

Note: To keep the example as simple and transparent as possible, only traffic rules relevant<br />

for the <strong>Kerio</strong> VPN configuration are mentioned.<br />

3. Customize DNS configuration as follows:<br />

• In the <strong>Kerio</strong> Control’s DNS module configuration, enable DNS forwarder<br />

(forwarding of DNS requests to other servers).<br />

• Enable the Use custom forwarding option and define rules for names in the<br />

filial.company.com domain. Specify the server for DNS forwarding by the IP<br />

address of the internal interface of the <strong>Kerio</strong> Control host (i.e. interface connected<br />

to the local network at the other end of the tunnel).<br />

Figure 23.17<br />

Headquarter — DNS forwarding settings<br />

• No DNS server will be set on interfaces of the <strong>Kerio</strong> Control host connected to the<br />

local networks LAN 1 and LAN 2.<br />

• On other computers set an IP address as the primary DNS server. This address<br />

must match the corresponding default gateway (10.1.1.1 or 10.1.2.1). Hosts in<br />

the local network can be configured automatically by DHCP protocol.<br />

Note: For proper functionality of DNS, the DNS database must include records for hosts<br />

in a corresponding local network. To achieve this, save DNS names and IP addresses of<br />

local hosts into the hosts file (if they use IP addresses) or enable cooperation of the DNS<br />

module with the DHCP server (in case that IP addresses are assigned dynamically to these<br />

hosts). For details, see chapter 9.1.<br />

4. Enable the VPN server and configure its SSL certificate (create a self-signed certificate if no<br />

certificate provided by a certification authority is available).<br />

327

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!