IWETHEY v. 0.3.0 | TODO
1,095 registered users | 0 active users | 0 LpH | Statistics
Login | Create New User
IWETHEY Banner

Welcome to IWETHEY!

New Win2k VPN configuration?
A client would like to establish a VPN link from a remote W2K laptop [eventualy via a G3 wireless connection - just an internet connection for now] to a LAN [connected via a low end, VPN compatible router]

For the prototype, we're using a Linksys BEFVP41 [need to verify the firmware revision].

I've been rying to build an ipSec tunnel, using documentation from Linksys and Microsoft.

Some outstanding issues

Is an ipSec tunnel appropriate?
The W2K configuration for the filters uses a fixed IP adress for the tunnel endpoints - the router / workstation addresses are assigned by the ISP using DHCP - I expect that a wireless workstation address will be quite volatile.



How to test / force a connection?
[I've downloaded M$'s netdiag utility - and it reports the configuration matches what I thought I put in - I'm following audit instructions from a M$ article now]
Can I force a connection by adding a known host name into LMHOSTS and performing net view //hostname ?


Any success stories with VPN's?
Dave Levitt

I'm not unemployed - I'm a consultant!
New Re: Win2k VPN configuration?
If there is any NAT in the equation anywhere along the route you want to establish the IPSec connection on, then you cannot use IPSec alone to establish the VPN.

You're probably better off using IPSec over something like PPTP or L2TP, NAT notwithstanding.


Peter
[link|http://www.debian.org|Shill For Hire]
[link|http://www.kuro5hin.org|There is no K5 Cabal]
[link|http://guildenstern.dyndns.org|Blog]
New Re: Win2k VPN configuration?
Thought it might be somthing involving NAT - even the ISP involved [Cablevision] uses the 10.0.0.0 net internally.

Time to stock up on smoke, mirrors and sacrifical chickens [KFC, Popeye's or Boston market?].
New Smoke, mirrors, and sacrificial chicken wings
Preferably at Hooters.
New Rationale:
IPSec depends on the IP header on the packet being unchanged. NAT does change these, and so IPSec breaks.


Peter
[link|http://www.debian.org|Shill For Hire]
[link|http://www.kuro5hin.org|There is no K5 Cabal]
[link|http://guildenstern.dyndns.org|Blog]
New you need 2 static public IP addresses for VPN
yes you can do it other ways but it is a mofo.
thanx,
bill
will work for cash and other incentives [link|http://home.tampabay.rr.com/boxley/resume/Resume.html|skill set]
"Fifty-one percent of a nation can establish a totalitarian regime, suppress minorities and still remain democratic." Correction: All that can be achieved with 51 percent of the voters!" Ilanna Mercer
     Win2k VPN configuration? - (dlevitt) - (5)
         Re: Win2k VPN configuration? - (pwhysall) - (3)
             Re: Win2k VPN configuration? - (dlevitt) - (2)
                 Smoke, mirrors, and sacrificial chicken wings - (wharris2)
                 Rationale: - (pwhysall)
         you need 2 static public IP addresses for VPN - (boxley)

I killed quite a few of my test rabbits when I first learned it.
51 ms