> For the complete documentation index, see [llms.txt](https://docs.pascom.net/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.pascom.net/en/setup/endpoints/vpn-connector.md).

# PASCOM VPN Connector setup

How to use the PASCOM VPN connector to connect your local network to your PASCOM cloud phone system

By using the PASCOM VPN connector it is possible to access local network services directly from the pascom.cloud hosted phone system. This could be necessary, for example, in order to authenticate phone system users against a locally installed Active Directory or to periodically import customer data from your ERP or CRM system into the PASCOM phone book.

{% hint style="success" %}
That PASCOM cloud phone systems include a Session Border Controller for mobile users, the VPN Connector is not necessary for and indeed is unsuitable for their connection.
{% endhint %}

### Transit Network and IP Addresses

The PASCOM VPN Connector establishes a Point to Point connection between your PASCOM instance and the OpenVPN client. The PASCOM instance is permanently assigned the IP address 172.16.23.1. For the purpose of the Transit Network, the address 172.16.23.0/24 is used. The OpenVPN client receives a random, however persistent IP address (always the same) from the Transit Network. You can determine this IP address via the OpenVPN client and use it enable access for you PASCOM instance to local client services.

## Configuration

### PASCOM Phone System

Log into your PASCOM phone system and under **Devices** > **Gateways** > **Add** and select new **VPN Access** from the list.

Enter a **name** for the VPN Connector and download the configuration via the **Save and Export** button.

### OpenVPN Client

The PASCOM VPN Connector is based on OpenVPN. Using the downloaded configuration, it is now possible to setup any OpenVPN client. OpenVPN clients are available for a number of Operationg Systems and Routers.

In order to access, for example, your locally installed Active Directory, simply install the OpenVPN client for Windows directly on your Windows Server and establish the connection to your PASCOM cloud phone system instance.

### Test the Connection

After successfully establishing the VPN, you should be in the position to reach the IP address of your PASCOM Instance 172.16.23.1 from the OpenVPN client:

```bash
ping 172.16.23.1

PING 172.16.23.1 (172.16.23.1): 56 data bytes
64 bytes from 172.16.23.1: icmp_seq=0 ttl=63 time=12.053 ms
64 bytes from 172.16.23.1: icmp_seq=1 ttl=63 time=11.945 ms
...
```

### Increase the reliability of the OpenVPN client on a Windows server

If you use the OpenVPN client on the Windows server, the VPN tunnel may not work after 24 hours and must be restarted. The connection is still active, but the TAP interface has an APIPA (169.x.x.x) address and therefore it cannot be reached via the tunnel.

In order to increase the reliability of the connection, the Windows option "DHCP media sense" be switched on.

First check the status of the "DHCP media sense" option in the Windows command prompt:

```shell
netsh interface ipv4 show global
```

If "DHCP media sense" is deactivated, activate it with the command:

```shell
netsh interface ipv4 set global dhcpmediasense = enabled
```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://docs.pascom.net/en/setup/endpoints/vpn-connector.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `build a script that syncs our docs to a CMS` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
