Re: VPN & NAT

From: mike (mike_at_heri.sd57.bc.ca)
Date: 03/22/04

  • Next message: Anil Gupte: "Error trying to install Qmail on Debian"
    To: gtg166a@mail.gatech.edu, debian-user@lists.debian.org
    Date: Sun, 21 Mar 2004 19:59:08 -0800
    
    

    On Sun, 21 Mar 2004 19:05:11 -0500, Matt Peter wrote
    > Hello All,
    >
    > I'm currently attempting to get VPN (windows 2000 remote access)
    > working through a nat setup. I'm having problems, and I know there
    > are some special things I need to setup to get this to work, but I'm
    > having trouble finding a good guide to this process. Does anyone
    > have a resources they could point me to for setting this up? The
    > box is currently running stable (2.2), but I can upgrade to 2.4 is
    > it's easier to VPN over NAT running

    I've only tested with a 2.4 kernel, but I've found that the ipmasq package
    installed will block vpn traffic.
    www.tldp.org may have some more info for NAT or VPN.
    I blank out all my rules with iptables and then throw in the one masqing rule
    to allow all traffic out. Perhaps try that for connecting to your VPN Server.
    Rule for ipmasq:
    # iptables -t nat -I POSTROUTING -s localnet/24 -j MASQUERADE

    If thats successful, then you'll have to edit your iptables so your
    NAT box is locked down of course.

    Cheers,
    Mike

    -- 
    To UNSUBSCRIBE, email to debian-user-request@lists.debian.org 
    with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
    

  • Next message: Anil Gupte: "Error trying to install Qmail on Debian"

    Relevant Pages

    • Re: Routing to remote office...
      ... one enable GRE protocol through the NAT setup? ... >> have got your VPN setup running! ... >> clients, But I am not able to connect to the VPN from the internet. ...
      (microsoft.public.backoffice.smallbiz2000)
    • Re: NATting both ways
      ... on my "VPN" network off a PIX 525. ... We are using ip nat inside and ip nat outside on our inside and ... creates a VPN to another router on a remote network. ... crypto map CLIENTMAP client authentication list default ...
      (comp.dcom.sys.cisco)
    • Re: VPN From W2K/Pro to W2K Server Doesn;t Work Through Firewall
      ... My belief is that your NAT ... My understanding is that IPSec AH protocol does not work with NAT devices ... IPSec operates in either one of two modes - transport mode or tunnel mode. ... provide a VPN remote access solution. ...
      (microsoft.public.win2000.security)
    • Re: VPN From W2K/Pro to W2K Server Doesn;t Work Through Firewall
      ... I did know you have Linux for NAT and my original suggestions still stand. ... Windows 2000 server through a Linux router with NAT. ... solution has IPsec passthrough, NAT breaks IPsec AH. ... regardless of what vendor you're using for NAT and VPN. ...
      (microsoft.public.win2000.security)
    • Re: Remote sync with Outlook via WiFi or other alternatives
      ... more about using VPN & PPTP. ... or are we still running into the same problem with NAT? ... No it's not difficutl to configure Wi-Fi or Cellular on a Pocket PC. ... > ability to sync with the Pocket PC) so you can keep everyone up to date. ...
      (microsoft.public.pocketpc.activesync)