Re: Setting up VPN

From: Alex Harsch (infodude_at_gmx.de)
Date: 07/17/04


Date: Sat, 17 Jul 2004 16:37:06 +0200

Captain Beefheart wrote:

> We've got a private network running through a firewall/gateway to the
> Internet (ie 192.168.1.* adddresses with the firewall using an IP given to
> us by our ISP, c/o a router they installed). The firewall runs Linux, of
> course.
>
> Our ISP has give us a range of IPs and we also run various servers outside
> of the firewall - mail, an FTP server etc
>
> A handful of our staff want to access the internal network from home to
> access a couple of file servers. The best way I can think of doing this is
> some kind of VPN system. But I've no idea how to set one up, either in
> terms of hardware or software.
>
> I presume that we'll need a PC with two network cards - one using an
> Internet IP and one which uses one of the local network addresses (and is
> therefore part of the private network)...?
Exactly, think about placing the vpn gwateway in the DMZ, on the firewall or
behind the firewall...
>
> Once this is in place, what software can I use to enact the VPN
> login/tunelling etc? Is there a specific Linux service script? If so, I
> could do with a GUI for it so that other non-Linux people can administrate
> it if need be.
The tunnel will be used whenever you address a IP of your private subnet, so
it is layer three/four and therefore transparent for your applications.
SMB/NFS, FTP, ssh and so on will work.
>
> Any help appreciated.
Hello,

using a 2.4 kernel, the best choice for an ipsec tunnel is prpably freeswan
(take a look at www.freeswan.org for dokumentation). Depending on your
security concirns there is quite a couple of free solutions, that are way
easier to set up, like opevpn, cipe,...).

Good luck, regards, Alex



Relevant Pages

  • Re: [SLE] Roadwarriors, VPN or pptp?
    ... > I'm using PPTP for some of our remote users, but that's because I have Win ... > poptop on a SnapGear firewall, though I'm planning to start moving to ipsec ... pptp is not as secure of a vpn ... Also recommended for consideration is Astaro Secure Linux. ...
    (SuSE)
  • Re: VPN From W2K/Pro to W2K Server Doesn;t Work Through Firewall
    ... I think I set up my Linux ipchains firewall to allow everything and to ... > If AH is being used in your VPN connection, you should see packets in your ... > use a sniffer such as windump [on your VPN client, ...
    (microsoft.public.win2000.security)
  • Re: Firewall, VPN and SQL Server
    ... Is someone suggesting to put the Linux Firewall/VPN in DMZ? ... have a linux VPN in another location, if you already have a firewall ... Forwarding traffic to another server especially when you are ...
    (comp.security.firewalls)
  • Re: Linux or BSD alternative to Windows Home Server
    ... My questions were about Gentoo vs. Linux for a sever, ... I will probably eventually have a dedicated firewall ... if you were to have a file server which is accessible ... I'm aware that I could probably create scripts to regularly backup ...
    (comp.os.linux.misc)
  • [fw-wiz] Newbie VPN setup/configuration question
    ... previously they were using a Linux system for their firewall. ... My husband was previously able to log into work via our ... firewall with VPN tunneling at home so we could use a VPN ...
    (Firewall-Wizards)