Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.networking > #892

Re: VPN problems

From Grant Edwards <invalid@invalid.invalid>
Newsgroups comp.os.linux.networking
Subject Re: VPN problems
Date 2011-12-08 14:53 +0000
Organization PANIX Public Access Internet and UNIX, NYC
Message-ID <jbqj25$j4g$1@reader1.panix.com> (permalink)
References <joshuafwhalen-A7339B.12532907122011@news.eternal-september.org> <4EDFBDDB.4060103@removethis.hesbynett.no> <jboiap$45h$1@reader1.panix.com> <joshuafwhalen-4FCF97.19250807122011@news.eternal-september.org> <4EE079BB.7050507@westcontrol.removethisbit.com>

Show all headers | View raw


On 2011-12-08, David Brown <david@westcontrol.removethisbit.com> wrote:

> I am not sure where you want the other end of your VPN tunnel - it has 
> to go somewhere.



> But assuming you want to let people at the office access something else 
> through the VPN tunnel, your easiest method is to set up one Linux box 
> (or BSD - pfSense might be an easy option for you) as a router so that 
> everyone's traffic passes through that box and out.  Don't try to get 
> individual machines on their own tunnels.

Even a $50 Buffalo WAP running OpenWRT would work fine as a router for
a small office.  OpenWRT supports both PPTP and OpenVPN.

> Anyway, you shouldn't be letting people with Macs connect directly to
> broadband - and certainly not people with Windows (or people with
> Linux, if they don't know what they are doing) - especially in your
> case, you should assume the broadband connection is full of evil
> hackers and worms.  You should always have your own firewall/router
> device between your vulnerable users and the outside internet.  And
> that is the ideal place to put your VPN tunnel (assuming everyone
> should have access to it).

I can't agree strongly enough.

> As for the blocking, check first that they are not just using DNS to 
> re-direct or hide the hosts.  If that's the case, then on your 
> firewall/router you want a local DNS server, and use something like 
> OpenDNS for the upstream server.
>
>> So... my error is GRE packets being blocked. What can I do about
>> that? Can I redirect to another port? How difficult?
>
> GRE packets don't have ports - it's a protocol on the same level as
> UDP, TCP/IP, ICMP, etc.  Only protocols on top of UDP and TCP/IP have
> ports.
>
> One of the nice things with OpenVPN is that it uses UDP (or TCP/IP,
> if it has to - but with higher latency) and so you can easily change
> the port if you want.
>
>> I'm visiting the recommended links now as soon as I finish typing
>> this. Thanks again for all the help. It's nice to know that what I
>> suspected of the GRE error is...well, what I suspected.

Whatever you do, do it it in _one_ place on a dedicated box (either a
WAP with OpenVPN, or a dedicated router/firewall box running Linux or
BSD).  Trying to configure a random collection of different machines
to all use VPNs is going to be hell...

-- 
Grant Edwards               grant.b.edwards        Yow! This is a NO-FRILLS
                                  at               flight -- hold th' CANADIAN
                              gmail.com            BACON!!

Back to comp.os.linux.networking | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

VPN problems Joshua Whalen <joshuafwhalen@gmail.com> - 2011-12-07 12:53 -0500
  Re: VPN problems David Brown <david.brown@removethis.hesbynett.no> - 2011-12-07 20:26 +0100
    Re: VPN problems Grant Edwards <invalid@invalid.invalid> - 2011-12-07 20:29 +0000
      Re: VPN problems Joshua Whalen <joshuafwhalen@gmail.com> - 2011-12-07 19:25 -0500
        Re: VPN problems David Brown <david@westcontrol.removethisbit.com> - 2011-12-08 09:47 +0100
          Re: VPN problems Grant Edwards <invalid@invalid.invalid> - 2011-12-08 14:53 +0000
            Re: VPN problems David Brown <david.brown@removethis.hesbynett.no> - 2011-12-08 17:19 +0100
          Re: VPN problems Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2011-12-08 18:36 +0100
      Re: VPN problems Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2011-12-08 18:25 +0100

csiph-web