
Supporting Multiple Users
Once your VPN expands to multiple users you must ensure
that IP addresses do not conflict by assigning each user their
own IP address.
Preventing IP Address Conflicts
How IP Addresses are Assigned to VPN Clients
The Local Address in VPN Tracker is the IP address that the Mac will be using
in the remote network when connected through VPN.
‣
If the Local Address field contains a fixed address this address is used. The
address must be unique among all users of the VPN connection
‣
If the Local Address field is left empty, the Mac’s actual local IP address (as
shown in System Preferences > Network) is used.
With multiple users, it’s easily possible that two users end up with the same
local IP address on their respective Macs (e.g. the private IP address
192.168.1.2). You will therefore have to use a fixed address when multiple
users connect to the VPN
Step 1 – Choose the Local Addresses
Choose the local addresses for your VPN clients so that
‣
the local addresses are not part of the VPN’s remote network (in most cases
the VPN gateway‘s LAN)
‣
each client has its own, unique IP address
Example: The VPN gateway ‘s LAN in our example is the network
192.168.13.0/24 (= 192.168.13.0/255.255.255.0). For the local addresses, choose an
arbitrary private network that is not part of this network, such as 10.1.2.0/24.
For each user, pick a different IP address from that network to be used as the
Local Address in VPN Tracker:
Please refer to your VPN gateway’s documentation for the maximum number
of VPN users that can connect to the device.
The IP addresses may not be part of the remote network
since your VPN gateway cannot act as an ARP proxy
Step 2 – Configure the Local Address in VPN Tracker
‣
Local Address: Enter the IP address that you have chosen for this user (here:
10.1.2.1 for the user Alice)
If your VPN gateway is not the default gateway (router) of its
network, you will have to ensure that traffic for the chosen IP
addresses is routed back to the VPN gateway instead of to the
usual default gateway (e.g. by adding a route on the default
gateway to the VPN gateway for these IPs).
16
Comentarios a estos manuales