IWETHEY v. 0.3.0 | TODO
1,095 registered users | 1 active user | 1 LpH | Statistics
Login | Create New User
IWETHEY Banner

Welcome to IWETHEY!

New VPN and Linux masq-ing firewall
Ok, I've tried reading the VPN-Masq-HOWTO and it's driving me nuts.

I've got Mandrake Corp Server 1.01 running on a P133. On the LAN side it's providing DHCP to several PCs. IP address are all in the 192.168.x.x range. On the WAN side I'm using PPPoE to connect to Verizon's ADSL service. Obviously, I'm masq-ing the non-routable IPs on the LAN side thru the firewall to the outside world. Everything works fine.

Now, my other half is getting sick and tired of having to use dialup to get into work and wants to use a VPN client on a W95 machine to do her work from home.

Through some experimentation, I find that with the VPN client installed, I can use any dialup ISP I want, but it doesn't seem to work using the ADSL line. I have allowed the VPN server at her work through the firewall and I can see UDP packets coming back on port 500, but they don't seem to go anywhere. I know that I need to use VPN MASQ, but I can't figure out if:

A) I need a patch to my 2.2.17 kernel. Everything on the VPN-MASQ-HOWTO mentions 2.2.x kernels from 2.2.16 and below. Nothing is mentioned about anything above that. Does the 2.2.17 kernel already have support for this?

B) I need a newer 2.2.x kernel that I can simple replace my existing one. Even if I get a newer kernel, do I still have to recompile the darn thing? I've never had *any* success doing that back in the RH 5.x days. I always screwed the damn thing up.

C) I am going to be forced to go to a 2.4.x kernel and learn HTF to use iptables. I have a hard enough time with remembering ipchains because I don't use it very often. If there's a way to do it, I'd prefer to stick with ipchains.

Oh, and I'll need layman's term and set-by-step instructions on this. :-)
New DOH!
I really shouldn't do these things late at night and with one eye open.

I see now I was wrong. There is a patch for the 2.2.17 kernel. Don't know how I missed it before.

At any rate, if any of you have done this before, please jump in with any pitfalls you found.

TIA
New A note on VPNs
Check your ISP's terms of service.

Many domestic ISPs explicitly forbid using VPNs on their network.

My ISP is no exception. From the [link|http://ntlworld.com/legals/user-policy.htm|NTLWorld User Policy] :

18. Use of Virtual Private Network (VPN)

As stated above, the ntl Internet and/or Interactive Services are for residential use only and we do not support the use of VPN. If we find you are using VPN via the ntl IP network we may instruct you to stop using it and you must comply with this request. This is in order to prevent problems to ntl (eg network performance) and other Internet users.


I suppose the reasoning is that if you have a need for VPNs then you're a business customer that they'd like to sell a more expensive package to.


Peter
[link|http://www.debian.org|Shill For Hire]
[link|http://www.kuro5hin.org|There is no K5 Cabal]
[link|http://guildenstern.dyndns.org|Blog]
     VPN and Linux masq-ing firewall - (n3jja) - (2)
         DOH! - (n3jja)
         A note on VPNs - (pwhysall)

Sanctioned by GRR.
33 ms