Emergency VPN Configuration
You set the gateway on the connector, prepare the VPN users by hand or from your Active Directory, and when the site is unreachable your engineers still get into the restored machines.
When the customer site is offline or compromised, the restore in the cloud cannot go through the connector. The Emergency VPN is the other road. It is an encrypted tunnel that brings your engineers inside the restored machines from any network, and gives those machines an Internet exit with a public IP.
Anteprima video temporaneamente non disponibile.
Apri il file direttamente →1. Set the gateway
- Open Connectors from the menu and pick the connector.
- In the page header, in the Emergency VPN panel, click the pencil icon.
- In the Gateway/CIDR field write the address of the router the protected devices use today, for example
192.168.1.1/24. - Confirm.
The panel now shows the gateway next to the VPN status, which stays Not active until you turn it on.
2. Prepare the users
Access is managed in the VPN & Access card, further down the same page.
To add users by hand click Add, type the username and confirm. Repeat for every person who will connect.
Otherwise you pull them straight from the customer Active Directory with the LDAP sync, covered below.
The users stay a list until the VPN is needed. They are actually created on the VPN machine when you start the DR with the Emergency VPN, and from that moment you download the configurations from the same card, one per user or all at once with Download all users conf. The file comes ready to use, so the client connects from any network without opening anything on the customer firewall.
3. LDAP Sync
If the people who need to get in are already in the customer domain, you read them from there instead of typing them again. The LDAP Sync section is at the bottom of the VPN & Access card.
- Click Configure LDAP.
- Fill in IP/Domain and Port, usually 389.
- Put the bind account credentials in Username and Password. A read only account is enough.
- In Base DN write the branch to start from, for example
DC=example,DC=local. - Confirm.
The Console tries the connection straight away. If the bind fails, if the search does not run or if the branch is empty, the error shows under the form and nothing is saved. When it works, the configuration is saved and the first sync starts on its own.
From then on the section shows Your local LDAP with an Online or Offline state and the Last sync date. The sync icon next to the title runs it again by hand, Change LDAP configuration reopens the form.
Who gets picked up and who does not
The filter is not configurable, it is fixed. Sefthy takes the person type user objects under the branch you gave and uses the sAMAccountName as the VPN username. The three system accounts Administrator, Guest and krbtgt are left out.
In the card table every row carries the Source column, which says Local / LDAP User or Manual Entry. Whoever comes from the domain has no delete icon, because your Active Directory is what governs them.
What happens to people who are removed
Every sync compares the domain list with the one Sefthy holds. Whoever no longer shows up under the branch you gave is dropped from the list and, if the VPN machine is already up, their access is deleted there too.
Two things to know. The sync does not run on its own, so after a change in the domain start it yourself with the icon next to the title. And an account that is merely disabled still shows up, because the filter looks at user objects and not at their state, so to take the VPN away from them they have to be removed from the branch.
Downloading the VPN configurations
LDAP users too stay a list until the VPN is needed. With the VPN machine up, Download VPN Config on each row opens two roads. For Windows a zip carrying the client and the configuration file, for Linux and macOS the .conf file alone, to be used with the WireGuard client.
Connectors with mixed DRs
One connector can serve several DRs on different plans. In the list of associated DRs, the ones without the PRO plan carry a warning triangle, because their restore cannot use the Emergency VPN.