LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 01-30-2003, 08:53 AM   #1
kalliste
LQ Newbie
 
Registered: Jan 2003
Location: UK
Distribution: RedHat and Slackware
Posts: 6

Rep: Reputation: 0
Exclamation Setting up Smoothwall VPN.


Im a bit of a linux newbie, so please bear with me here.

I have set up my first firewall using Smoothwall GPL. Its simple, rocks, and Im very happy with it, if anyone else is considering doing the same.

Now I want to sort out the VPN option so I can connect to another base and do remote admin/file sharing and that sort of thing. The problem is that the only part of the Smoothwall documentation that is confusing is the VPN config.

I dont quite get the whole left/right/next hop thing.

Can anyone help and explain to me how I do this. I have 2 bases (lets call them BASE X and BASE Y).

Both have seperate ISP's, but the main config is exactly the same...both on DSL, both using DHCP and the firewall is NAT translating to 192.168.X.X

BASE X has internal network 192.168.1.x/24 and external network A.B.C.D/29. This firewalls Green Eth Card is set to 192.168.1.1

BASE Y has internal network 192.168.2.x/24 and external network E.F.G.H/28. This firewalls Green Eth Card is set to 192.168.2.1

My question is, how do I fill in the following fields (in both BASE X and BASE Y)

name
left
left next hop
left subnet
right
right next hop
right subnet

I have tried it already, but It told me that the subnet was wrong. I dont want to screw it up, so was hoping that someone who has done this already can basically tell me the settings using the algebraic settings as above.

And There's a virtual (or real if you live close to Leeds, UK) pint in it for anyone who can help....

Thanks.
Dylan
 
Old 02-01-2003, 09:22 AM   #2
peter_robb
Senior Member
 
Registered: Feb 2002
Location: Szczecin, Poland
Distribution: Gentoo, Debian
Posts: 2,458

Rep: Reputation: 48
Yeah,
it's a pity it is so simple, and we cannot understand it until it works!!! You're certainly not alone with this...

First,
the next hop is for "routing".
If you exit the VPN you are unencrypted, and maybe on an incorrect network segment, so the 'next hop' is a "routing" function to push the packets to the next router/gateway down the line until they find the correct network, rather than being dumped on Smoothie's local network...Oops! Not correct. Read the thread below please!
Use them if you need to, or leave them blank.
2nd, make sure you are using the v1.0 software rather than the Beta versions. Some people are playing with the iptables scripts forgetting that there cannot be any SNATing on the ipsec channel!!
3rd, enter the subnets that you use in the local network, so, without a hop, match the settings on each Smoothie's GREEN interface
4th, make sure you use different GREEN ip ranges so local routing knows they are remote addresses...
5th, make the ip numbers in 'left' & 'right' as static as possible, even if this means leaving the VPN up all the time.
6th, copy the "secret" to each machine.
7th, make sure the information is "identical" in each Smoothie. "left" is eg 195.117.7.xxx in each Smoothie. Don't swap the left/right numbers at each end...

Comments...
Especially for Dynamic numbers... figure out how often your DSL numbers rotate. If it's a real bugger, get static numbers. This is how often you will need to change the left/right numbers.
There is a Smoothwall GPL mailing-list forum from their website for any newbie/technical questions, and an archive for historically "similar" questions.

Last edited by peter_robb; 02-28-2003 at 10:35 AM.
 
Old 02-03-2003, 06:26 AM   #3
kalliste
LQ Newbie
 
Registered: Jan 2003
Location: UK
Distribution: RedHat and Slackware
Posts: 6

Original Poster
Rep: Reputation: 0
Thanks for that Peter. I think i must still be doing something wrong though.

I have set up the following:

Name = VPN1
Left = Green Interface IP (leeds base)
Left Next Hop = Red Interface IP (leeds base)
subnet= Green Interface Subnet (255.255.255.0)

Right= Green Interface IP (manchester base)
Right Next Hop= Red Interface IP (manchester base)
subnet= Green Interface Subnet (255.255.255.0)

I have clicked ADD but get the message: RIGHT SUBNET IS INVALID.

Um....? Any ideas? Perhaps im just being really thick...

Kind Regards.
Dylan
 
Old 02-28-2003, 10:30 AM   #4
peter_robb
Senior Member
 
Registered: Feb 2002
Location: Szczecin, Poland
Distribution: Gentoo, Debian
Posts: 2,458

Rep: Reputation: 48
Sorry for the earlier mistake...

From the built-in Smoothie help file in the VPN tag...
"Name: A simple name to reference this connection. Use lowercase letters only.
Left = vpn1 (Leeds)
Right = vpn2 (Manchester)

Left/Right: The internet IP address of the Left/Right side of the connection.
Left = Leeds RED ip number
Right = Manchester RED ip number

Left/Right next hop: The next hop from Left/Right side back into the Internet (i.e. the default gateway of the left/right RED device).
Left = ISP gateway ip number Leeds Smoothwall is using in routing table
Right = ISP gateway ip number Manchester Smoothwall is using in routing table

Left/Right subnet: The network of the left/right hand side (e.g. 192.168.0.0/24 would include 192.168.0.*).
Left = Leeds network 192.168.1.0/24
Right = Manchester network 192.168.2.0/24

Secret: The password for the connection.

Last edited by peter_robb; 02-28-2003 at 10:43 AM.
 
Old 03-13-2003, 05:04 AM   #5
grrt
LQ Newbie
 
Registered: Mar 2003
Location: Netherlands
Distribution: Smoothwall / RH 8.0
Posts: 1

Rep: Reputation: 0
question from another newbie

Left/Right subnet: The network of the left/right hand side (e.g. 192.168.0.0/24 would include 192.168.0.*).
Left = Leeds network 192.168.1.0/24
Right = Manchester network 192.168.2.0/24

Hello guys, I am trying to set up a vpn as well using your information. But I don't really understand the information about the above (/24) so I would like to ask Kalliste what the exact subnets are he used to make his vpn work.

regards, gerry
 
Old 04-03-2003, 03:49 PM   #6
chrisknight
Member
 
Registered: Jan 2003
Location: ohio
Distribution: CentOS7.6
Posts: 157

Rep: Reputation: 15
The * is a wildcard.
so, 192.168.1.* for you
and, 192.168.2.* for the other end will work.
 
Old 03-26-2011, 04:49 AM   #7
PhantomGriffin
LQ Newbie
 
Registered: Mar 2011
Distribution: Ubuntu and Fedora
Posts: 2

Rep: Reputation: 0
Cool First Post - Explaining Subnetting

Quote:
Originally Posted by grrt View Post
Left/Right subnet: The network of the left/right hand side (e.g. 192.168.0.0/24 would include 192.168.0.*).
Left = Leeds network 192.168.1.0/24
Right = Manchester network 192.168.2.0/24

Hello guys, I am trying to set up a vpn as well using your information. But I don't really understand the information about the above (/24) so I would like to ask Kalliste what the exact subnets are he used to make his vpn work.

regards, gerry
Gerry I hope I can answer your question about the 192.168.1.0/24

The first thing I believe I need to tell you about is the 24. The 24 is another way of saying 255.255.255.0

remembering that you can use the numbers from 0 to 255 that is 256 possible numbers to use. 256 in decimal is 11111111 in binary. Therefore in binary the subnet is 11111111.11111111.11111111.00000000 ok now... after explaining that now the question is how many 1 binary bits are used when the subnet mask is 255.255.255.0? 24, that is where the 24 comes from.

Now because 255.255.255 is used for the subnet mask that means the subnet is 192.168.1

I hope that clears up any confusion

Regards

Phantom
 
Old 10-19-2012, 11:56 AM   #8
marcus556
LQ Newbie
 
Registered: Mar 2010
Posts: 4

Rep: Reputation: 0
What if you have VLans configured? What subnets do you put it in then? The subnet of the device you want to retrieve files from or the subnet of the router?

Also is this a site to site VPN or can it be access outside from any network?

Last edited by marcus556; 10-19-2012 at 12:10 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
SmoothWall Distribution Networking: VPN question jobless_joe Linux - Networking 6 09-03-2004 11:09 AM
smoothwall gpl2b4 VPN question SSBN Linux - Networking 0 05-25-2003 02:54 PM
VPN = Smoothwall 2.0 and Netgear FVL328 Router tekquest Linux - Networking 0 04-14-2003 07:38 PM
Smoothwall VPN Again kalliste Linux - Networking 1 02-28-2003 10:13 AM
Smoothwall, VPN and Laptops bigwave Linux - Networking 0 10-17-2001 08:29 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 06:36 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration