31.03.2014 Views

Kerio Control — Administrator's Guide - Kerio Software Archive

Kerio Control — Administrator's Guide - Kerio Software Archive

Kerio Control — Administrator's Guide - Kerio Software Archive

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Example of <strong>Kerio</strong> VPN configuration: company with a filial office<br />

Figure 2<br />

Headquarter — default traffic rules for <strong>Kerio</strong> VPN<br />

3. Customize DNS configuration as follows:<br />

• In the <strong>Kerio</strong> <strong>Control</strong>’s DNS module configuration, enable DNS forwarder<br />

(forwarding of DNS requests to other servers).<br />

• Enable the Use custom forwarding option and define rules for names in the<br />

filial.company.com domain. Specify the server for DNS forwarding by the IP<br />

address of the internal interface of the <strong>Kerio</strong> <strong>Control</strong> host (i.e. interface connected<br />

to the local network at the other end of the tunnel).<br />

Figure 3<br />

Headquarter — DNS forwarding settings<br />

• No DNS server will be set on interfaces of the <strong>Kerio</strong> <strong>Control</strong> host connected to the<br />

local networks LAN 1 and LAN 2.<br />

• On other computers set an IP address as the primary DNS server. This address<br />

must match the corresponding default gateway (10.1.1.1 or 10.1.2.1). Hosts in<br />

the local network can be configured automatically by DHCP protocol.<br />

For proper functionality of DNS, the DNS database must include records for<br />

hosts in a corresponding local network. To achieve this, save DNS names and IP<br />

addresses of local hosts into the hosts table (if they use IP addresses) or enable<br />

cooperation of the DNS module with the DHCP server (in case that IP addresses<br />

are assigned dynamically to these hosts).<br />

4. Enable the VPN server and configure its SSL certificate (create a self-signed certificate if no<br />

certificate provided by a certification authority is available).<br />

50

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!