Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.networking > #891

Re: VPN problems

Path csiph.com!x330-a1.tempe.blueboxinc.net!usenet.pasdenom.info!weretis.net!feeder4.news.weretis.net!feeder2.ecngs.de!ecngs!feeder.ecngs.de!Xl.tags.giganews.com!border1.nntp.ams.giganews.com!nntp.giganews.com!local2.nntp.ams.giganews.com!nntp.lyse.net!news.lyse.net.POSTED!not-for-mail
NNTP-Posting-Date Thu, 08 Dec 2011 02:48:12 -0600
Message-ID <4EE079BB.7050507@westcontrol.removethisbit.com> (permalink)
Date Thu, 08 Dec 2011 09:47:55 +0100
From David Brown <david@westcontrol.removethisbit.com>
User-Agent Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20111105 Thunderbird/8.0
MIME-Version 1.0
Newsgroups comp.os.linux.networking
To Joshua Whalen <joshuafwhalen@gmail.com>
Subject Re: VPN problems
References <joshuafwhalen-A7339B.12532907122011@news.eternal-september.org> <4EDFBDDB.4060103@removethis.hesbynett.no> <jboiap$45h$1@reader1.panix.com> <joshuafwhalen-4FCF97.19250807122011@news.eternal-september.org>
In-Reply-To <joshuafwhalen-4FCF97.19250807122011@news.eternal-september.org>
Content-Type text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding 7bit
Lines 71
X-Usenet-Provider http://www.giganews.com
X-AuthenticatedUsername NoAuthUser
X-Trace sv3-1Tu3q5rVzLwITrjWaXCZeOOHj4kp2Ia/3BVnImYCUbmwhDPO5PG7zAy0qLOkvPna1lf39k0p5rCDTJg!B2Qet41hQL2jLmR3e/QPvvc+rewnjIXX4Y2iPHxO6T5zyzPGEF7vhQCnMzaBeq8Yd/qqXVd+OlU2!j+Dh9y//YVc=
X-Complaints-To abuse@altibox.no
X-Abuse-and-DMCA-Info Please be sure to forward a copy of ALL headers
X-Abuse-and-DMCA-Info Otherwise we will be unable to process your complaint properly
X-Postfilter 1.3.40
X-Original-Bytes 4876
Xref x330-a1.tempe.blueboxinc.net comp.os.linux.networking:891

Show key headers only | View raw


On 08/12/2011 01:25, Joshua Whalen wrote:
> WOW.
>
> The amount of response and useful knowledge... awesome. I'm not used to
> this low a signal to noise ration in usenet. Thank you.
>

That would be a /high/ signal-to-noise ratio :-)

> Here's the problem with openVPN (which I definitely will check into, it
> sounds like it might solve the problem easiest of all, but...):
>
> If you've been watching TV or reading the paper, I'm sure you've heard
> that #OWS has a fancy office on lower broadway these days thanks to a
> generous donor. HOWEVER, that's all we have. An office. With an evil
> broadband provider who blocks almost everything. We have maybe 5
> computers of our own, mostly macs, 1 windows box. We have hundreds of
> people coming in and out of here every day, bringing their own machines.
> Some run various linuxen, some OS X (anything from tiger to lion.
> Haven't seen any system 7 yet, but don't doubt it might walk in the door
> any second now...), and a lotta various windozen. Some people run
> WIn2000, others run 7, whatever I do, it has to take minimal config on
> all of these, because I'm just one guy and I'm the only fulltime ( or
> almost full time ) tech around here. That's actually why I chose pptp. I
> knew it was old and clunky, but everything already has it installed. I
> never know what is going to walk in the door and scream "WHY CAN'T I
> ACCESS dreamhost.com?" Yes, believe it or not, they have dreamhost of
> all the innocuous hosts in the universe, blocked. That's basically why
> I'm setting it up, to give our people an easy way to route around the
> blocks.
>

I am not sure where you want the other end of your VPN tunnel - it has 
to go somewhere.

But assuming you want to let people at the office access something else 
through the VPN tunnel, your easiest method is to set up one Linux box 
(or BSD - pfSense might be an easy option for you) as a router so that 
everyone's traffic passes through that box and out.  Don't try to get 
individual machines on their own tunnels.

Anyway, you shouldn't be letting people with Macs connect directly to 
broadband - and certainly not people with Windows (or people with Linux, 
if they don't know what they are doing) - especially in your case, you 
should assume the broadband connection is full of evil hackers and 
worms.  You should always have your own firewall/router device between 
your vulnerable users and the outside internet.  And that is the ideal 
place to put your VPN tunnel (assuming everyone should have access to it).

As for the blocking, check first that they are not just using DNS to 
re-direct or hide the hosts.  If that's the case, then on your 
firewall/router you want a local DNS server, and use something like 
OpenDNS for the upstream server.

> So... my error is GRE packets being blocked. What can I do about that?
> Can I redirect to another port? How difficult?
>

GRE packets don't have ports - it's a protocol on the same level as UDP, 
TCP/IP, ICMP, etc.  Only protocols on top of UDP and TCP/IP have ports.

One of the nice things with OpenVPN is that it uses UDP (or TCP/IP, if 
it has to - but with higher latency) and so you can easily change the 
port if you want.

> I'm visiting the recommended links now as soon as I finish typing this.
> Thanks again for all the help. It's nice to know that what I suspected
> of the GRE error is...well, what I suspected.
>
> Joshua

Back to comp.os.linux.networking | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

VPN problems Joshua Whalen <joshuafwhalen@gmail.com> - 2011-12-07 12:53 -0500
  Re: VPN problems David Brown <david.brown@removethis.hesbynett.no> - 2011-12-07 20:26 +0100
    Re: VPN problems Grant Edwards <invalid@invalid.invalid> - 2011-12-07 20:29 +0000
      Re: VPN problems Joshua Whalen <joshuafwhalen@gmail.com> - 2011-12-07 19:25 -0500
        Re: VPN problems David Brown <david@westcontrol.removethisbit.com> - 2011-12-08 09:47 +0100
          Re: VPN problems Grant Edwards <invalid@invalid.invalid> - 2011-12-08 14:53 +0000
            Re: VPN problems David Brown <david.brown@removethis.hesbynett.no> - 2011-12-08 17:19 +0100
          Re: VPN problems Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2011-12-08 18:36 +0100
      Re: VPN problems Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2011-12-08 18:25 +0100

csiph-web