LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 10-14-2003, 10:31 PM   #1
satimis
Senior Member
 
Registered: Apr 2003
Posts: 3,695

Rep: Reputation: 56
Searching for VPN article


Hi all folks,

I am searching Internet on VPN. Kindly advise where can I find a technical article on introduction of VPN. Pointers will be appreciated.

Thanks in advance.

B.R.
satimis
 
Old 10-20-2003, 03:11 AM   #2
rbelknap
LQ Newbie
 
Registered: Oct 2003
Posts: 5

Rep: Reputation: 0
I am still working on getting it to work on my Redhat 9.0 server, but a good place to start is http://www.poptop.org/.
 
Old 10-20-2003, 08:09 AM   #3
satimis
Senior Member
 
Registered: Apr 2003
Posts: 3,695

Original Poster
Rep: Reputation: 56
Quote:
Originally posted by rbelknap
I am still working on getting it to work on my Redhat 9.0 server, but a good place to start is http://www.poptop.org/.
Hi,

Noted with thanks

B.R.
satimis
 
Old 10-20-2003, 09:29 AM   #4
phtkiller
LQ Newbie
 
Registered: Oct 2003
Posts: 13

Rep: Reputation: 0
i trying to build a vpn ppp server with callback. i tried poptop but it didnt work properly..
Does anyone here have any tutorial? would be very helpfull!
my system "redhat 9.0"
 
Old 10-20-2003, 09:30 AM   #5
phtkiller
LQ Newbie
 
Registered: Oct 2003
Posts: 13

Rep: Reputation: 0
I forgot...
If you have something for me to help me out, please send it to my email

pht@bind.ro
 
Old 10-20-2003, 10:26 PM   #6
satimis
Senior Member
 
Registered: Apr 2003
Posts: 3,695

Original Poster
Rep: Reputation: 56
Quote:
Originally posted by phtkiller
i trying to build a vpn ppp server with callback. i tried poptop but it didnt work properly..
Does anyone here have any tutorial? would be very helpfull!
my system "redhat 9.0"
Hi,

Please try

http://www.poptop.org

to see whether it helps

B.R.
satimis
 
Old 10-22-2003, 11:23 PM   #7
cmisip
Member
 
Registered: Aug 2002
Posts: 189

Rep: Reputation: 30
I have successfully used Freeswan to connect a redhat 9 roadwarrior or windows xp roadwarrior via vpn tunnel to the home machine running redhat 9.

http://cmisip.home.insightbb.com/freeswan.htm
 
Old 10-23-2003, 05:51 AM   #8
satimis
Senior Member
 
Registered: Apr 2003
Posts: 3,695

Original Poster
Rep: Reputation: 56
Quote:
Originally posted by cmisip
I have successfully used Freeswan to connect a redhat 9 roadwarrior or windows xp roadwarrior via vpn tunnel to the home machine running redhat 9.

http://cmisip.home.insightbb.com/freeswan.htm
Hi,

Congragulation.

I am interested to test freeswan or other vpn packages and have no idea how to proceed.

I have 2 desktop boxes running RH8,0 and RH9 respectively,each with 2 NICs and a broadband connection. What hardware I need to add? What shall be their setup? How to connect them to make this test.

Could you please provide me some advice. Thanks in advance.

B.R.
satimis
 
Old 10-23-2003, 09:47 PM   #9
cmisip
Member
 
Registered: Aug 2002
Posts: 189

Rep: Reputation: 30
I use vpn two ways : to encrypt my wireless connection between the laptop and my gateway at home, and to encrypt the connection between the laptop and the home gateway via the internet when I am on the road. I assume you want the second option where you want to connect two computers across the internet zone. I have not done that kind of setup but I believe the way to do this is through a host to host vpn connection between the two machines. It's like a modified roadwarrior setup where "this PC" is left and "that PC" is right. Therefore, the definitions of left and right are reversed in each PC. Look at the first example of how I setup the MYLAPTOP and MYLIVINGROOM machines using rsa keys host to host to encrypt the wireless lan. Except, substititute the internet IP address of the two machines for left and right. Omit the leftsubnet and rightsubnet field. No values for nexthop are needed. You may have to read further down in the article as you may get the "no nexthop" error. Look at the relevant part of the modified _updown script.

If this is not what you want, provide a little more detail with what exactly you want to accomplish. The nic cards are irrelevant since I assume you are connecting across the internet zone. It would be pointless to encrypt two machines in a wired lan unless you have untrusted pcs in the same network. It is always prudent to encrypt a wireless connection because it is like a "all you can eat data buffet for everybody" within range of the wireless router.
 
Old 10-24-2003, 01:37 AM   #10
satimis
Senior Member
 
Registered: Apr 2003
Posts: 3,695

Original Poster
Rep: Reputation: 56
Hi cmisip,

Thanks for your detail information.

I have 2 desktop PCs and one (1) ISP. While I connect one PC to Internet another PC is isolated from outside World. I have no router for sharing broadband. I may do masquerating using 1 PC to connect broadband and sharing the later/Internet with another PC.

If I want to test freeswan whether I need to purchase additional hardware. OR present hardware will be sufficient for the test.

Kindly advise. Thanks in advance.

B.R.
satimis
 
Old 10-24-2003, 05:43 PM   #11
cmisip
Member
 
Registered: Aug 2002
Posts: 189

Rep: Reputation: 30
I guess I dont understand what you need freeswan for. If all you want is to allow both computers to access the internet via a single isp, all you need to do is to configure one of them (the one with the isp connection) as a two interface shorewall system (or something similar). One of its network interface card will connect to the cable modem. The other will connect to the other pc.
The first pc will perform IP masquerading for the second pc. Both will then have internet connections.
 
Old 10-24-2003, 11:45 PM   #12
satimis
Senior Member
 
Registered: Apr 2003
Posts: 3,695

Original Poster
Rep: Reputation: 56
Quote:
Originally posted by cmisip
I guess I dont understand what you need freeswan for. If all you want is to allow both computers to access the internet via a single isp, all you need to do is to configure one of them (the one with the isp connection) as a two interface shorewall system (or something similar). One of its network interface card will connect to the cable modem. The other will connect to the other pc.
The first pc will perform IP masquerading for the second pc. Both will then have internet connections.
Hi,

Sorry maybe I have not explained clear in my previous postings.

I want to explore freeswan, not masquerading which I am now doing on Shorewall. With one ISP I would have problem to perform freeswan test unless I get a wireless router. Therefore I tried to seek your advice whether there will be other solution excluding purchasing a wireless router.

Thanks

B.R.
satimis
 
Old 10-25-2003, 12:42 AM   #13
cmisip
Member
 
Registered: Aug 2002
Posts: 189

Rep: Reputation: 30
so you just want to establish a vpn connection between the two computers you have in your wired home network as a test.

Have you gotten a successful "ipsec verify" yet on both computers? This is clearly explained in the documentation. You have to get past this first, then configure /etc/ipsec.conf and transfer your rsa.

What are your computers internal IP's?
 
Old 10-25-2003, 03:55 AM   #14
satimis
Senior Member
 
Registered: Apr 2003
Posts: 3,695

Original Poster
Rep: Reputation: 56
Quote:
Originally posted by cmisip
so you just want to establish a vpn connection between the two computers you have in your wired home network as a test.

Have you gotten a successful "ipsec verify" yet on both computers? This is clearly explained in the documentation. You have to get past this first, then configure /etc/ipsec.conf and transfer your rsa.

What are your computers internal IP's?
Hi,

Can I connect 2 computers with a crossover cable for this test?

I have not yet installed 'freeswan' on these 2 computers for this test

# ifconfig
shows both computer having same internal IP
127.0.0.1

B.R.
satimis
 
Old 10-25-2003, 11:33 AM   #15
cmisip
Member
 
Registered: Aug 2002
Posts: 189

Rep: Reputation: 30
If you are already masquerading, then there is an ethernet connection between the two computers ( you can access the internet on both using one isp right?). If you can ping one computer from the other, then you dont need another cable. If the computer connected to the cable modem has eth0 and eth1 (with etho connected to the cable modem) and eth1 connected to the second pc, what I need is ifconfig eth1 for that pc. The other pc which is not connected to the cable modem, what i need is ifconfig eth0 (assuming eth0 is what connects it to pc number 1).

The ip 127.0.0.1 is the internal loopback address which you wont be needing for this test. This address refers to "this" machine. All linux machines have this and programs refer to this to access services running in "this" machine.

I will also need the output of /sbin/route.


Go ahead and install f rees/wan on both computers and get a successful ipsec verify.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
VPN: linux VPN server behind Linksys router hamish Linux - Networking 14 08-25-2005 08:42 PM
VPN Question Win98->internet->Router->Linux VPN Server->Win2k Server patrickrea Linux - Networking 1 08-10-2004 02:09 AM
How do i connect Ciscos VPN client to Checkpoint VPN server Klas Linux - Networking 1 11-29-2003 08:00 AM
MASQ VPN to VPN Router hakcenter Linux - Networking 0 06-26-2003 04:14 PM
rh article tundra Linux - General 10 06-24-2002 12:05 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 12:58 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration