LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-07-2003, 02:51 AM   #1
mcukstorm
LQ Newbie
 
Registered: Jul 2003
Posts: 2

Rep: Reputation: 0
Routing PPTP through router running linux 2.4.x kernel


I am trying to route vpn(pptp) traffic from a win2k client on the internal network to a remote win2k server on the internet, i am currently using ipchains. Has any one got any ideas, all the sites i have found mention using kernel patches and utilities but most of the links are broken and there are no kernel patches for anything passed 2.2.x. Has it been built into the later kernels?

(Running RedHat 7.3, custom Kernel Build version 2.4.18-3, i686 platform)

Any help would be much appreaciated.

Grant
 
Old 07-07-2003, 09:33 AM   #2
german
Member
 
Registered: Jul 2003
Location: Toronto, Canada
Distribution: Debian etch, Gentoo
Posts: 312

Rep: Reputation: 30
re: Routing PPTP through kernel 2.4

I know this is a linux forum, but if you want to do that without a kernel patch or recompile, OpenBSD supports all of that (using pf as opposed to iptables, which is actually extremely user-friendly by comparison IMHO), including PPTP, in the default install. Also if you decide to, OBSD kernel compiles are easier to configure, and if you look at http://www.openbsd.org/errata.html you'll notice they haven't had to release a single patch for their latest version.

HTH

Ben.
 
Old 07-07-2003, 09:50 AM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
I'm not a VPN expert, but from what I've read the general opinion is PPTP is a MICROS~1/b0rken/surrogate implementation of something vaguely resembling IPSEC. IOW, unsafe, regardless of O.S..

Here's some LinuxQuestions.org Search results for PPTP to get you going. Google around for POPTOP and/or PPTPPROXY.
 
Old 07-07-2003, 10:01 AM   #4
german
Member
 
Registered: Jul 2003
Location: Toronto, Canada
Distribution: Debian etch, Gentoo
Posts: 312

Rep: Reputation: 30
I've heard the same thing. He didn't ask for security advice . PPTP VPN's are an outdated technology, and not really suitable for the world wide guerilla war of today. I have seen this tutorial praised by various people that seem to know their stuff, but it seems to require a significant time investment to get working:

http://www.secureops.com/vpn/ipsecvpn.html

Personally I think public key SSH and proper firewalling are the safest way to go, but I may get my eyebrows burnt off when the flames jump out my screen for saying that :P.

B.
 
Old 07-07-2003, 11:30 AM   #5
mcukstorm
LQ Newbie
 
Registered: Jul 2003
Posts: 2

Original Poster
Rep: Reputation: 0
Thks

Thanks to all for your help, pptpproxy worked perfectly

I will have to take a look at the BSD family when i have a spare few hours.

Grant
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
router issue - kernel routing tables? FliesLikeABrick Linux - Networking 2 11-02-2005 08:21 PM
PPTP (MPPE) routing? nicholai Linux - Networking 0 02-16-2005 07:10 AM
Problem routing PPTP VPN connections - Mandrake 10.1 kalahari875 Linux - Networking 2 01-22-2005 09:55 AM
Routing or a pptp connection problem? l2g Linux - Networking 4 05-04-2004 05:29 PM
linux routing VS cisco router shoot2kill Linux - Networking 5 07-01-2002 10:31 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:09 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration