The icom Connectivity Suite – VPN is a service of INSYS icom for the simple and secure network connection of locations, plants, control centers and mobile devices via a Virtual Private Network (VPN).
.png)
Situation
An IP device is located on a local network with internet access. An INSYS icom router is to be used to enable secure remote access to this device via the VPN network of the icom Connectivity Suite – VPN. It is not possible to make changes to the local network, for example to create a dedicated WAN network that is separate from the plant network.
You are using your own VPN network?
If you are using your own VPN network instead of the icom Connectivity Suite – VPN, you can use our converter tool to convert the configuration file for that VPN network into an ASCII configuration file for the router, so that you can then upload it under Configuring the OpenVPN connection below. This Configuration Guide explains how to convert your OpenVPN configuration file into an ASCII configuration file for INSYS routers.
Solution
An INSYS icom router is installed on the local network. The router is configured to establish an internet connection via the gateway on the local network and to connect to the icom Connectivity Suite – VPN.
Risks from opening up the network!
It is strongly recommended that you use separate LAN and WAN networks. Only use the configuration set out below if the requirements of your local network do not allow for this.
Please note that this configuration means the entire local network, including the default gateway, will be accessible via the VPN tunnel. Ensure that you have implemented the necessary security measures in your LAN network beforehand.
For the purposes of this example, we will assume the following addresses on the network:
The plant network is in the IP range 192.168.178.0/24.
The internet gateway on the local network has the IP address 192.168.178.1.
The router gets the IP address 192.168.178.100.
.png)
It is assumed that you already have an account for the icom Connectivity Suite – VPN, as described in this Configuration Guide.
It is assumed that you have already added the configuration PC to the icom Connectivity Suite – VPN, as described in this Configuration Guide, and connected to it as described in this Configuration Guide.
It is assumed that you have already added the router to the icom Connectivity Suite – VPN with the IP address 192.168.178.100 without netmapping, as described in this Configuration Guide.
.png)
It is assumed that the router is in its default settings. This Configuration Guide explains how to reset the router.
It is assumed that you have installed the router as described in the Quick Installation Guide and connected it to the system network.
Do not use the Startup Wizard!
Usually, using the Startup Wizard would be the best way to configure the router. In this particular case, however, it is simpler and more straightforward to carry out the configuration manually. Configuring the router using the Startup Wizard would create a separate WAN interface, which would cause routing conflicts.
Download the configuration file for the router as described in the Manual Configuration section of this Configuration Guide.
Open the user interface of the router: https://insys.icom
Configuring the OpenVPN connection
The router must be configured to connect to the OpenVPN network of the icom Connectivity Suite – VPN. This is done via the ASCII configuration file.
Click To manual configuration on the splash screen under Manual configuration when the splash screen appears or enter your credentials if the router is no longer in factory settings.
Open the Administration → Profile page and click on (Upload) in the ASCII configurations section.
Select the configuration file you downloaded earlier and click on Submit.
Click on behind the just uploaded configuration, click on Upload ASCII configuration and select Apply ASCII configuration.
.png)
The OpenVPN settings for connecting to the icom Connectivity Suite - VPN are now stored in the profile.
Configuring the Internet connection
To establish an internet connection, a WAN chain must be created using the OpenVPN connection that has just been configured using the configuration file. The internet gateway on the local network must be set as the default gateway.
Open the Network → WAN / Internet page and click on (Add) to add a new WAN chain.
Click under Interfaces in WAN chain on Add interface + and select under Interfaces the OpenVPN interface openvpn1.
Check the option Additional connection check, select Ping and specify the address 198.18.0.1 to perform a regular check of the connection to the OpenVPN server.
.png)
Click on Submit.
Open the Network → DHCP page and click on (Edit). Disable the checkbox Active to disable the DHCP server, because a second DHCP server in the network would cause conflicts.
.png)
Click on Submit.
Open the Network → Routing page and click on (Add) in the Static routes section. Select as Interface net1, select as Route type Default route, select as Gateway static IP address and specify the asdress 192.168.178.1 of the local Internet gateway.
.png)
Click on Submit.
Open the Network → Hostnames / DNS page and click on (Edit) in the DNS settings section. Specify the address 192.168.178.1 of the local internet gateway as First IPv4 DNS server address.
.png)
Click on Submit.
Configuring the firewall settings
A number of firewall rules have already been created via the configuration file. In addition, firewall rules must be configured for DNS and NTP queries.
Open the Network → Firewall / NAT page and click on (Edit) in the Firewall section. Check the checkbox IP filter for IPv4 activated and click on Submit.
.png)
Click in the IP filter section on (Add) to add an IP filter rule for DNS queries over TCP and configure it accordingly:
Description: DNS Out
Packet direction: OUTPUT
IP version: All
Protocol: TCP
Output interface: net1
Destination port: 53
.png)
Click on Submit.
Click on (Add) again to add an IP filter rule for DNS queries via UDP and configure it accordingly:
Description: DNS Out
Packet direction: OUTPUT
IP version: All
Protocol: TCP
Output interface: net1
Destination port: 53
Click on Submit.
Click on (Add) again to add an IP filter rule for NTP queries and configure it accordingly:
Description: NTP Out
Packet direction: OUTPUT
IP version: All
Protocol: TCP
Output interface: net1
Destination port: 123
Click on Submit.
Click in the Source NAT section on (Add) to add a masquerading rule for net1 and configure it accordingly:
Description: Masquerade
Type: Masquerade
Protocol: TCP
Output interface: net1
.png)
Click on Submit.
Configuring a regular time synchronisation
Setting the correct date and time on the router is very important for certificate-based authentication, such as a VPN tunnel. You should therefore ensure that the time is updated regularly, as described in this guide.
Setting up a user
Under icom OS, it is not possible to commission a router without creating a user account to protect the router against unauthorised access to the user interface. Please use a strong password for this purpose.
Open the Administration → User page and click on (Edit) in the User section behind the initial user entry.
Enter User name and Password and select as Group Read/write.
Click on Submit.
Activating the profile
All the configurations have been completed. The profile just needs to be activated for the changes to take effect.
Accessibility of the router!
Please note that once the profile has been activated, the router will no longer be accessible via the default address 192.168.1.1. It will then be accessible on the local network via the new address 192.168.178.100 or via the icom Connectivity Suite – VPN.
You may need to adjust the settings on your configuration PC to regain access to the router within the plant network.
Activate the profile with a click on ACTIVATE PROFILE in the title bar.
Open the Administration → Time / date page and click in the Time synchronisation section on (Update) to synchronise the router’s time.
Results check
You can see whether the router is connected to the icom Connectivity Suite - VPN on the Status → Dashboard page of the router as well as in the icom Connectivity Suite - VPN on the VPN → Devices page.
Troubleshooting
The status of the WAN chain and their interfaces is displayed on the
Status → Dashboard page. If an interface does not achieve the online condition, its condition can also be examined on this page.When configuring the OpenVPN connection with the Startup wizard, only the most important settings are made, but in most cases these are sufficient to establish a connection. If this is not possible, check the detailed settings of the OpenVPN connection. To do this, click on in the line of the created OpenVPN interface in the Network → Interfaces menu in the OpenVPN section to check or edit the settings. Click on to extended view at the top right to show the detailed settings.
In case the OpenVPN server requires a static key for authentication and encryption (tls-crypt) or only for authentication (tls-auth) additionally, or a user name/password combination for authentication additionally, these need to be configured also.
If no network traffic is achieved, the tools integrated in the router can be used for debugging.
Check in the
Status → Log-View menu the messages in the OpenVPN log.Disable the IP filters for IPv4 in the Network → Firewall / NAT menu under Settings IP filter to check whether incorrect filter settings are the reason for connection problems.