Re: OpenVPN [was: IPSec VPN docs]

From: Brian Chase (networkr0_at_cfl.rr.com)
Date: 03/26/04

  • Next message: Florin Andrei: "Re: OpenVPN [was: IPSec VPN docs]"
    Date: Fri, 26 Mar 2004 14:49:41 -0500
    To: For users of Fedora Core releases <fedora-list@redhat.com>
    
    

    Another thing you can try is another hardware IPSec VPN that I use today
    and prefer the service, documentation, and support over DLINK

    http://www.zyxel.com/product/category.php?indexFlagvalue=1021873683

    Florin Andrei wrote:

    > On Sun, 2004-03-21 at 12:07, Mark Haney wrote:
    >
    >>I'm trying to get a VPN setup between my FC1 box at home and a DLink
    >>DFL300 at my office so I can do some things securely without having to
    >>make the 30 minute drive in to work to fix stuff. I've googled the
    >>subject and the amount of documentation is pretty immense. Can someone
    >>give me a shortened version what I need to configure or point me to a good
    >>step by step doc on how to do it?
    >
    >
    > Well, if IPSec is not a specific requirement, and if you actually could
    > use any VPN solution that's simple to install, secure and feature-rich,
    > have a look at OpenVPN:
    >
    > http://openvpn.sourceforge.net/
    >
    > A brief "cookbook recipe" HOWTO:
    >
    > http://fedoranews.org/contributors/florin_andrei/openvpn/
    >
    > IPSec VPN (like FreeS/WAN) is nice because it's compatible with all
    > kinds of VPN devices and software.
    > However, it can be a pain to install, even more so if you're using
    > Windows clients (but Linux is not a lot simpler, especially if you have
    > non-geek users). Also, it is very, very picky if there are firewalls in
    > between, especially if you go through NAT.
    >
    > OpenVPN is very simple to install, it does not require weird kernel
    > patches, it is firewall-friendly, works just fine with Windows (and
    > Solaris, and BSD), can tunnel through proxies, etc.
    >
    > It is not a typical "SSL VPN" - i mean, it is not a browser-based VPN,
    > even though it's using SSL to encrypt the tunnel. Think of it as exactly
    > the same thing as FreeS/WAN except it's using SSL instead of IPSec;
    > otherwise, it can route arbitrary IP protocols, it does not require a
    > browser, etc.
    > Just like FreeS/WAN, but without the pain.
    >

    -- 
    Brian Chase			Phone:  386-775-5366
    2345 Hillside Ave.		Fax:    309-276-2048
    Orange City, FL  32763		Email:  networkr0@cfl.rr.com
    http://openalternatives.net
    -- 
    fedora-list mailing list
    fedora-list@redhat.com
    To unsubscribe: http://www.redhat.com/mailman/listinfo/fedora-list
    

  • Next message: Florin Andrei: "Re: OpenVPN [was: IPSec VPN docs]"

    Relevant Pages

    • RE: IPSec VPN & NATD (problem with alias_address vs redirect_addr ess)
      ... I should be able to do 5 VPN IPSec connection at the same ... the ESP packet coming on 208.x.y.120 is mapped directly to ... IPSec VPN & NATD (problem with alias_address vs ...
      (freebsd-isp)
    • RE: IPSec VPN & NATD (problem with alias_address vs redirect_addr ess)
      ... I should be able to do 5 VPN IPSec connection at the same ... the ESP packet coming on 208.x.y.120 is mapped directly to ... IPSec VPN & NATD (problem with alias_address vs ...
      (freebsd-net)
    • Re: stop installation
      ... Do you know if your VPN is an SSL VPN or IPsec VPN? ... Often times ISPs ...
      (microsoft.public.windowsxp.configuration_manage)
    • Re: different ipsec inbound sessions thru nat
      ... >> My office has a 2811 acting as a Ipsec VPN gateway for roaming users. ... The translated WAN IP of your router is one IP, ... UPD packets port 4500 but then the 2nd connection never completes. ...
      (comp.dcom.sys.cisco)
    • Re: A RAS/VPN "Is it just me?" question
      ... You have a T1 at the office connected to a Cisco ... Then you say you have a Dlink at the office and a Dlink at ... If you are adventurous you could have me try to vpn from one of my ... >> router? ...
      (microsoft.public.windows.server.sbs)