LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-02-2005, 12:21 PM   #1
longtex
Member
 
Registered: Aug 2004
Location: Texhuahua
Distribution: RedHat 6,7,9,EL; SuSE 9.2 Pro, Knoppix 3.4/.7/.9, Fedora Core 4
Posts: 87

Rep: Reputation: 15
Any SonicWall Users???


Hey... anyone have experience using SonicWalls?
 
Old 08-02-2005, 03:10 PM   #2
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,659
Blog Entries: 4

Rep: Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941
More than I ever expected or wished to.

I found out, for example, that the racoon daemon did not support the XAUTH style of authorization that so many Sonicwall people use. I hacked the ipsec-tools-0.6b2 package, racoon daemon, (using an update that I found on the internet and adapted) to connect properly using this authorization style.

The source file is here, for now anyway: http://www.sundialservices.com/downl...ll-06b2.tar.gz

I don't know how or where to send it to become part of the 'official' source tree, nor do I know what is "officially" being done with regard to XAUTH and Sonicwall. All I knew was that I had a paying customer I couldn't talk to! I did not originate it, but managed to get the stuff working and to fix a few problems along the way. (The original patch developer simply assumed that the authentication would use certificates rather than pre-shared-key [PSK].)

Last edited by sundialsvcs; 08-02-2005 at 03:11 PM.
 
Old 08-03-2005, 11:23 AM   #3
longtex
Member
 
Registered: Aug 2004
Location: Texhuahua
Distribution: RedHat 6,7,9,EL; SuSE 9.2 Pro, Knoppix 3.4/.7/.9, Fedora Core 4
Posts: 87

Original Poster
Rep: Reputation: 15
Quote:
Originally posted by sundialsvcs
More than I ever expected or wished to.

I found out, for example, that the racoon daemon did not support the XAUTH style of authorization that so many Sonicwall people use. I hacked the ipsec-tools-0.6b2 package, racoon daemon, (using an update that I found on the internet and adapted) to connect properly using this authorization style.

The source file is here, for now anyway: http://www.sundialservices.com/downl...ll-06b2.tar.gz

I don't know how or where to send it to become part of the 'official' source tree, nor do I know what is "officially" being done with regard to XAUTH and Sonicwall. All I knew was that I had a paying customer I couldn't talk to! I did not originate it, but managed to get the stuff working and to fix a few problems along the way. (The original patch developer simply assumed that the authentication would use certificates rather than pre-shared-key [PSK].)
Hi - thanks for the interesting response.

I've not gotten into using SonicWalls much other than connecting sites with actual SW hardware, so I'm not aware of racoon, or what exactly problems you're having. It sounds like you're getting into (and through) the SWs from outside systems without a SW attached. I've done a little of this, using the SW software, but I thought it was probably a lot better idea to use the hardware, particularly since it seems that only one software-only client is allowed per machine.

I have right now four clients, three with two sites each, and one with four. I have TZ170s at all sites, including my office and at home. Two sites have occasional trouble, but that seems to be due to the 'net connection. One site is very peculiar, in that it flatly refuses to let any communications through - from ME - although the SWs themselves show the "green light" indicating a tunnel exists... and I can get to it by going to one of the others and thence to the trooublesome one - it's only ME that it has problems with - the other three sites in its own subnet are fine. Basically, three sites use the fourth as the location of file servers using NFS and Samba, and everything seems to be working just fine (as long as the ISP keeps things connected!).

So I'm primarily looking at the SW as a VPN system, with the firewalling as a very welcome side benefit - what about you?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Sonicwall to OpenSwan Roadwarrior shane_kelly55 Linux - Security 3 08-02-2005 12:22 AM
Linux server behind Sonicwall jbstew32 Linux - Networking 1 11-12-2003 10:18 AM
Does Sonicwall use linux for the OS illtbagu Linux - Security 5 11-08-2003 03:29 AM
IPtables & Sonicwall etron Linux - Security 1 09-23-2003 03:55 PM
Using syslog server for sonicwall sorry Linux - General 1 01-17-2002 08:01 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:54 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration