IWMAC VPN - Setup and Information
Typically, a Site-to-Site VPN is set up between the customer and IWMAC. This tunnel is mainly used for administration of the IWMAC PC or device, typically via port 81 and 5900. The IWMAC-PC reports data over the internet to IWMAC.
Customer information required
Before we can set up the tunnel, the customer must fill in the following information:
- Subnet/Host (Encryption Domain), e.g.
172.18.19.0/24or172.18.19.20/32 - Peer/Public IP, e.g.
172.18.55.89 - LAN address to be assigned to the IWMAC PC
- Desired encryption method
Required contact details
We need the name, phone number and email address of a person who can test the VPN tunnel once it is set up. Our supplier Atea will also contact this person for exchange of PSK (Preshared Key).
VPN settings (IWMAC)
-
IWMAC Subnet/Host (Encryption Domain):
192.168.220.0/24 -
IWMAC Peer/Public Address:
89.248.6.154
ISAKMP / Phase 1
- Encryption: AES256
- Authentication: SHA1
- DH Group: 2
- Lifetime: 28800 seconds
IPSEC / Phase 2
- Replay Detection: Yes
- Perfect Forward Secrecy: Yes
- Encryption: AES256
- Authentication: SHA1
- DH Group: 2
- Lifetime: 3600 seconds
Ports that need to be opened
- From IWMAC to customer: 81/TCP, 5900/TCP, 20000/TCP
- From customer to IWMAC: 81/TCP, 20000/TCP
192.168.220.0/24, the following IPs must be allowed: 192.168.220.90, .201, .100 and .2.IP configuration for IWMAC-PC
The customer must enter the following details for the IWMAC-PC:
- IP address
- Subnet mask
- Default gateway
- DNS server
This information is returned to IWMAC for further setup.
More information can be found at www.kiona.com