LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 12-21-2009, 06:41 PM   #1
worm5252
Member
 
Registered: Oct 2004
Location: Atlanta
Distribution: CentOS, RHEL, HP-UX, OS X
Posts: 567

Rep: Reputation: 57
is there a Citrix CAG style VPN for Linux?


I was thinking about setting up a VPN server here at home to tinker with. I have a second DSL line to test with. Is there a VPN system that works for both Linux and Windows clients similar to Citrix Access Gateway (CAG)?

I am looking for a Client Server relationship that is initiated via a web login. If not I still would like a client server relationship and not just setting up a static VPN connection.
 
Old 12-22-2009, 05:58 PM   #2
beadyallen
Member
 
Registered: Mar 2008
Location: UK
Distribution: Fedora, Gentoo
Posts: 209

Rep: Reputation: 36
Not quite sure what you mean by 'client/server', but I assume you mean that it's not just a two machine tunnel (i.e. you want many clients connecting to one server). If so, then give OpenVPN a look.
AFAIK there's no web interface to it and the client software needs installing on all machines that will use it, but it's relatively easy to set up, and very flexible. Perfect for a small number of users connecting to your home machine. It works on both Linux and Windows, and is much easier than a full blown IPSEC VPN. Plus it handles stuff like NAT and proxy servers fairly well.

I don't personally know of any web based systems (well open source anyway). Perhaps someone else will. I'm always a little suspicious of such interfaces though. My problem (whether justified or not) is that potentially anyone can connect to it. And since users are required to log into a web form, the password has to be remembered, and therefore not all that great (certainly less good than the public key encryption available with openvpn).
Of course, it may be that the citrix system uses secure tokens etc, which is a good thing, and my fears could be entirely unjustified. Just my prejudices really.

Also, (and I know this is just investigation), but do you really want users to be able to connect from anywhere. I know this is a supposed selling point of these web based SSL VPNs, but it has some pretty serious security implications. Even with a secure token and ultra strong password, a user could (and trust me, someone would) visit the local internet cafe and log in to your VPN on a virus infested Windows box. It doesn't matter how good the password is, or that the Citrix App is 'secure' and bug free. An attacker just got a free pass to your network. I would personally prefer to have a least some control over which machines are connecting to a network.

Wow, I've gone completely OT....
Give OpenVPN a try
 
Old 12-22-2009, 10:24 PM   #3
worm5252
Member
 
Registered: Oct 2004
Location: Atlanta
Distribution: CentOS, RHEL, HP-UX, OS X
Posts: 567

Original Poster
Rep: Reputation: 57
Well the idea of the web portal is mainly for software deployment. I would have an LDAP Domain Controller interfacing with the web portal for user authentication and access control.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
e.g., BSD style (Slackware) vs. SystemV style startup scripts haertig Slackware 5 01-03-2009 10:52 PM
Compiling kernel Debian style or Native style ? Raynus Debian 1 06-16-2008 06:56 AM
Citrix and linux colinstu Linux - Software 7 02-27-2006 04:58 AM
Citrix vpn access client problems plythgam Linux - Software 3 11-09-2005 06:01 PM
VIM-style wrapping to OpenOffice style schmmd Linux - Software 1 12-21-2004 06:50 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 06:36 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration