Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.misc > #5327

PPTP and NAT, IPSec and vpnc to Draytek Vigor

From Chris Davies <chris-usenet@roaima.co.uk>
Newsgroups comp.os.linux.misc
Subject PPTP and NAT, IPSec and vpnc to Draytek Vigor
Date 2012-05-18 01:09 +0100
Organization Roaima. Harrogate, North Yorkshire, UK
Message-ID <oigg89x2j4.ln2@news.roaima.co.uk> (permalink)

Show all headers | View raw


I seem to be getting squashed between a rock and a hard place, and Google
doesn't appear to be my saviour - this time.

I need to connect from my home office to a client's site using VPN. They
have a Draytek Vigor and can offer IPSec or PPTP.

1. PPTP won't work across NAT without help. My router - a Thomson TG585
with version 7 firmware -  doesn't have a PPTP ALG to support GRE,
and it's sufficiently locked down by the ISP that I'm not sure I could
safely upgrade the firmware. (I know the my firmware's revision doesn't
have PPTP support as neither my laptop nor my smartphone can establish
a PPTP session through the router, whereas the smartphone can at least
connect via GPRS/3G. And Googling does appear to support this discovery).

2. My IPSec client of choice, vpnc, appears to make the Draytek router
complain about IKE being Aggressive and they won't play ball together.

3. OpenVPN isn't supported by the Draytek.


I have considered a number of options, but none of them really appeals
to me "as is". Maybe I've missed something, or one of you can offer me
some advice.

a. Upgrade the router firmware. This is an unknown as it's a locked-down
router provided by my ISP and (apparently) unless the newer firmware is
also appropriately locked down it won't load.

b. Replace the router firmware with DD-WRT. I don't believe DD-WRT
supports ADSL; it's just routing and wireless, isn't it?

c. Buy another router. This seems overkill for this one project.

d. Persuade the client to (allow me to) install OpenVPN on one of their
Windows servers, and bypass the Draytek's VPN capabilities entirely. I
can't see them being that impressed by this idea, really.

e. Persude the client to allow me to run an ssh tunnel from one of their
fileservers (running Linux-ish) back to my own server, over which I can
then tunnel TCP based connections. Ugly but plausible.

f. Try and climb the learning curve for OpenSWAN/FreeSWAN - and the
Draytek's IPSec configuration - before Christmas.

Thoughts, pointers, and advice gratefully received.

Cheers,
Chris

Back to comp.os.linux.misc | Previous | NextNext in thread | Find similar | Unroll thread


Thread

PPTP and NAT, IPSec and vpnc to Draytek Vigor Chris Davies <chris-usenet@roaima.co.uk> - 2012-05-18 01:09 +0100
  Re: PPTP and NAT, IPSec and vpnc to Draytek Vigor Stan Bischof <stan@worldbadminton.com> - 2012-05-18 13:30 +0000
    Re: PPTP and NAT, IPSec and vpnc to Draytek Vigor Chris Davies <chris-usenet@roaima.co.uk> - 2012-05-19 01:07 +0100
      Re: PPTP and NAT, IPSec and vpnc to Draytek Vigor The Natural Philosopher <tnp@invalid.invalid> - 2012-05-19 01:16 +0100
  Re: PPTP and NAT, IPSec and vpnc to Draytek Vigor J G Miller <miller@yoyo.ORG> - 2012-05-19 10:58 +0000
    Re: PPTP and NAT, IPSec and vpnc to Draytek Vigor Chris Davies <chris-usenet@roaima.co.uk> - 2012-05-23 19:57 +0100
      Re: PPTP and NAT, IPSec and vpnc to Draytek Vigor J G Miller <miller@yoyo.ORG> - 2012-05-24 13:15 +0000
        Re: PPTP and NAT, IPSec and vpnc to Draytek Vigor Chris Davies <chris-usenet@roaima.co.uk> - 2012-05-24 15:40 +0100
          Re: PPTP and NAT, IPSec and vpnc to Draytek Vigor J G Miller <miller@yoyo.ORG> - 2012-05-24 15:49 +0000
            Re: PPTP and NAT, IPSec and vpnc to Draytek Vigor Chris Davies <chris-usenet@roaima.co.uk> - 2012-05-24 23:54 +0100
              Re: PPTP and NAT, IPSec and vpnc to Draytek Vigor J G Miller <miller@yoyo.ORG> - 2012-05-25 00:10 +0000
                Re: PPTP and NAT, IPSec and vpnc to Draytek Vigor Chris Davies <chris-usenet@roaima.co.uk> - 2012-05-25 08:51 +0100

csiph-web