Path: csiph.com!x330-a1.tempe.blueboxinc.net!usenet.pasdenom.info!weretis.net!feeder4.news.weretis.net!feeder2.ecngs.de!ecngs!feeder.ecngs.de!Xl.tags.giganews.com!border1.nntp.ams.giganews.com!nntp.giganews.com!local2.nntp.ams.giganews.com!nntp.lyse.net!news.lyse.net.POSTED!not-for-mail NNTP-Posting-Date: Thu, 08 Dec 2011 02:48:12 -0600 Message-ID: <4EE079BB.7050507@westcontrol.removethisbit.com> Date: Thu, 08 Dec 2011 09:47:55 +0100 From: David Brown User-Agent: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20111105 Thunderbird/8.0 MIME-Version: 1.0 Newsgroups: comp.os.linux.networking To: Joshua Whalen Subject: Re: VPN problems References: <4EDFBDDB.4060103@removethis.hesbynett.no> In-Reply-To: Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Lines: 71 X-Usenet-Provider: http://www.giganews.com X-AuthenticatedUsername: NoAuthUser X-Trace: sv3-1Tu3q5rVzLwITrjWaXCZeOOHj4kp2Ia/3BVnImYCUbmwhDPO5PG7zAy0qLOkvPna1lf39k0p5rCDTJg!B2Qet41hQL2jLmR3e/QPvvc+rewnjIXX4Y2iPHxO6T5zyzPGEF7vhQCnMzaBeq8Yd/qqXVd+OlU2!j+Dh9y//YVc= X-Complaints-To: abuse@altibox.no X-Abuse-and-DMCA-Info: Please be sure to forward a copy of ALL headers X-Abuse-and-DMCA-Info: Otherwise we will be unable to process your complaint properly X-Postfilter: 1.3.40 X-Original-Bytes: 4876 Xref: x330-a1.tempe.blueboxinc.net comp.os.linux.networking:891 On 08/12/2011 01:25, Joshua Whalen wrote: > WOW. > > The amount of response and useful knowledge... awesome. I'm not used to > this low a signal to noise ration in usenet. Thank you. > That would be a /high/ signal-to-noise ratio :-) > Here's the problem with openVPN (which I definitely will check into, it > sounds like it might solve the problem easiest of all, but...): > > If you've been watching TV or reading the paper, I'm sure you've heard > that #OWS has a fancy office on lower broadway these days thanks to a > generous donor. HOWEVER, that's all we have. An office. With an evil > broadband provider who blocks almost everything. We have maybe 5 > computers of our own, mostly macs, 1 windows box. We have hundreds of > people coming in and out of here every day, bringing their own machines. > Some run various linuxen, some OS X (anything from tiger to lion. > Haven't seen any system 7 yet, but don't doubt it might walk in the door > any second now...), and a lotta various windozen. Some people run > WIn2000, others run 7, whatever I do, it has to take minimal config on > all of these, because I'm just one guy and I'm the only fulltime ( or > almost full time ) tech around here. That's actually why I chose pptp. I > knew it was old and clunky, but everything already has it installed. I > never know what is going to walk in the door and scream "WHY CAN'T I > ACCESS dreamhost.com?" Yes, believe it or not, they have dreamhost of > all the innocuous hosts in the universe, blocked. That's basically why > I'm setting it up, to give our people an easy way to route around the > blocks. > I am not sure where you want the other end of your VPN tunnel - it has to go somewhere. But assuming you want to let people at the office access something else through the VPN tunnel, your easiest method is to set up one Linux box (or BSD - pfSense might be an easy option for you) as a router so that everyone's traffic passes through that box and out. Don't try to get individual machines on their own tunnels. Anyway, you shouldn't be letting people with Macs connect directly to broadband - and certainly not people with Windows (or people with Linux, if they don't know what they are doing) - especially in your case, you should assume the broadband connection is full of evil hackers and worms. You should always have your own firewall/router device between your vulnerable users and the outside internet. And that is the ideal place to put your VPN tunnel (assuming everyone should have access to it). As for the blocking, check first that they are not just using DNS to re-direct or hide the hosts. If that's the case, then on your firewall/router you want a local DNS server, and use something like OpenDNS for the upstream server. > So... my error is GRE packets being blocked. What can I do about that? > Can I redirect to another port? How difficult? > GRE packets don't have ports - it's a protocol on the same level as UDP, TCP/IP, ICMP, etc. Only protocols on top of UDP and TCP/IP have ports. One of the nice things with OpenVPN is that it uses UDP (or TCP/IP, if it has to - but with higher latency) and so you can easily change the port if you want. > I'm visiting the recommended links now as soon as I finish typing this. > Thanks again for all the help. It's nice to know that what I suspected > of the GRE error is...well, what I suspected. > > Joshua