Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.os.linux.networking > #892
| From | Grant Edwards <invalid@invalid.invalid> |
|---|---|
| Newsgroups | comp.os.linux.networking |
| Subject | Re: VPN problems |
| Date | 2011-12-08 14:53 +0000 |
| Organization | PANIX Public Access Internet and UNIX, NYC |
| Message-ID | <jbqj25$j4g$1@reader1.panix.com> (permalink) |
| References | <joshuafwhalen-A7339B.12532907122011@news.eternal-september.org> <4EDFBDDB.4060103@removethis.hesbynett.no> <jboiap$45h$1@reader1.panix.com> <joshuafwhalen-4FCF97.19250807122011@news.eternal-september.org> <4EE079BB.7050507@westcontrol.removethisbit.com> |
On 2011-12-08, David Brown <david@westcontrol.removethisbit.com> wrote:
> I am not sure where you want the other end of your VPN tunnel - it has
> to go somewhere.
> But assuming you want to let people at the office access something else
> through the VPN tunnel, your easiest method is to set up one Linux box
> (or BSD - pfSense might be an easy option for you) as a router so that
> everyone's traffic passes through that box and out. Don't try to get
> individual machines on their own tunnels.
Even a $50 Buffalo WAP running OpenWRT would work fine as a router for
a small office. OpenWRT supports both PPTP and OpenVPN.
> Anyway, you shouldn't be letting people with Macs connect directly to
> broadband - and certainly not people with Windows (or people with
> Linux, if they don't know what they are doing) - especially in your
> case, you should assume the broadband connection is full of evil
> hackers and worms. You should always have your own firewall/router
> device between your vulnerable users and the outside internet. And
> that is the ideal place to put your VPN tunnel (assuming everyone
> should have access to it).
I can't agree strongly enough.
> As for the blocking, check first that they are not just using DNS to
> re-direct or hide the hosts. If that's the case, then on your
> firewall/router you want a local DNS server, and use something like
> OpenDNS for the upstream server.
>
>> So... my error is GRE packets being blocked. What can I do about
>> that? Can I redirect to another port? How difficult?
>
> GRE packets don't have ports - it's a protocol on the same level as
> UDP, TCP/IP, ICMP, etc. Only protocols on top of UDP and TCP/IP have
> ports.
>
> One of the nice things with OpenVPN is that it uses UDP (or TCP/IP,
> if it has to - but with higher latency) and so you can easily change
> the port if you want.
>
>> I'm visiting the recommended links now as soon as I finish typing
>> this. Thanks again for all the help. It's nice to know that what I
>> suspected of the GRE error is...well, what I suspected.
Whatever you do, do it it in _one_ place on a dedicated box (either a
WAP with OpenVPN, or a dedicated router/firewall box running Linux or
BSD). Trying to configure a random collection of different machines
to all use VPNs is going to be hell...
--
Grant Edwards grant.b.edwards Yow! This is a NO-FRILLS
at flight -- hold th' CANADIAN
gmail.com BACON!!
Back to comp.os.linux.networking | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
VPN problems Joshua Whalen <joshuafwhalen@gmail.com> - 2011-12-07 12:53 -0500
Re: VPN problems David Brown <david.brown@removethis.hesbynett.no> - 2011-12-07 20:26 +0100
Re: VPN problems Grant Edwards <invalid@invalid.invalid> - 2011-12-07 20:29 +0000
Re: VPN problems Joshua Whalen <joshuafwhalen@gmail.com> - 2011-12-07 19:25 -0500
Re: VPN problems David Brown <david@westcontrol.removethisbit.com> - 2011-12-08 09:47 +0100
Re: VPN problems Grant Edwards <invalid@invalid.invalid> - 2011-12-08 14:53 +0000
Re: VPN problems David Brown <david.brown@removethis.hesbynett.no> - 2011-12-08 17:19 +0100
Re: VPN problems Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2011-12-08 18:36 +0100
Re: VPN problems Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2011-12-08 18:25 +0100
csiph-web