Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.networking > #1013

Re: VPN, L2TP, and problems with netmasks...

Path csiph.com!x330-a1.tempe.blueboxinc.net!newsfeed.hal-mli.net!feeder3.hal-mli.net!newsfeed.hal-mli.net!feeder1.hal-mli.net!npeer01.iad.highwinds-media.com!news.highwinds-media.com!feed-me.highwinds-media.com!postnews.google.com!glegroupsg2000goo.googlegroups.com!not-for-mail
From Marcin Łukasik <marcin@milea.pl>
Newsgroups comp.os.linux.networking
Subject Re: VPN, L2TP, and problems with netmasks...
Date Tue, 24 Jan 2012 03:51:42 -0800 (PST)
Organization http://groups.google.com
Lines 32
Message-ID <1122003.1781.1327405902247.JavaMail.geo-discussion-forums@vbhz6> (permalink)
References <5386824.2020.1327323263265.JavaMail.geo-discussion-forums@yqkm20> <jfkf89$2fft$1@saria.nerim.net>
Reply-To comp.os.linux.networking@googlegroups.com
NNTP-Posting-Host 88.211.55.18
Mime-Version 1.0
Content-Type text/plain; charset=ISO-8859-1
X-Trace posting.google.com 1327406351 27038 127.0.0.1 (24 Jan 2012 11:59:11 GMT)
X-Complaints-To groups-abuse@google.com
NNTP-Posting-Date Tue, 24 Jan 2012 11:59:11 +0000 (UTC)
Cc pascal.news@plouf.fr.eu.org
In-Reply-To <jfkf89$2fft$1@saria.nerim.net>
Complaints-To groups-abuse@google.com
Injection-Info glegroupsg2000goo.googlegroups.com; posting-host=88.211.55.18; posting-account=OiVxTgoAAACXw4XJNjmeLPj4lFCRkU_f
User-Agent G2/1.0
X-Google-Web-Client true
Xref x330-a1.tempe.blueboxinc.net comp.os.linux.networking:1013

Show key headers only | View raw


On Monday, January 23, 2012 8:17:12 PM UTC, Pascal Hambourg wrote:

> This is so wrong, even it does what you need.
> Classes are deprecated.

You have to set it up for the interfaces, so I did.
But when I said "I've allocated 10.9.9.0/24" I meant "VPN users use a range of 10.9.9.1 - 10.9.9.254".


> As L2TP usually transports PPP sessions, I guess it is IPCP, the
> protocol used by PPP to negotiate IP parameters such as the remote and
> local addresses is IPCP. AFAIK, it does not allow to "push" routes like
> OpenVPN does. So you need to add the route by other means when the
> tunnel is up. Any decent PPP software should be able to do it.

Thank you.
True, it doesn't "push" routes. I can add them manually and it works fine, but I'm trying to avoid this.
Not all the users know much about computers and VPNs, and I want to make their life (and mine) easier.
WIndows adds a route to 10.0.0.0 (so /8), which makes it work.
Mac adds a route to 10.9.9.0 (so /24), which makes 10.9.8.0 inaccessible via VPN.

My best option was to route all the traffic via VPN on Mac. In this case a default route is created and routed via the VPN.
This of course isn't ideal...

But Apple Server was able to "push" some setting, that created either two routes (to 10.9.8.0 and to 10.9.9.0) or extended the subnet allocated by the system from /24, to something wider.

The only thing that comes to my mind is "pushing" two router IPs to the client (so 10.9.8.254 and 10.9.9.254). Then the system would probably create two routes.
But I am not sure whether this is possible by design?
The client gets local and remote IPs for the tunnel, and probably the gateway. But can client get two gateways? What other settings can be sent over IPCP?

Thanks a lot,
Marcin

Back to comp.os.linux.networking | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

VPN, L2TP, and problems with netmasks... Marcin Łukasik <marcin@milea.pl> - 2012-01-23 04:54 -0800
  Re: VPN, L2TP, and problems with netmasks... Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-01-23 21:17 +0100
    Re: VPN, L2TP, and problems with netmasks... Marcin Łukasik <marcin@milea.pl> - 2012-01-24 03:51 -0800
    Re: VPN, L2TP, and problems with netmasks... ibuprofin@painkiller.example.tld.invalid (Moe Trin) - 2012-01-24 14:02 -0600

csiph-web