All of lore.kernel.org
 help / color / mirror / Atom feed
From: "John A. Sullivan III" <john.sullivan@nexusmgmt.com>
To: Roksana Boreli <Roksana.Boreli@nicta.com.au>
Cc: netfilter@lists.netfilter.org
Subject: RE: Multiple IPSEC VPNs through a firewall based on 2.4.2X kernel
Date: Wed, 25 Aug 2004 07:29:20 -0400	[thread overview]
Message-ID: <1093433311.2034.36.camel@localhost> (raw)
In-Reply-To: <09D3F703EF3B0A4CBE28449EA9F3D3206F1D7A@nicta-atp-mail.in.nicta.com.au>

Thanks for the clarification.  Does the Cisco Linux client support any
form of NAT Traversal? If it does, that is the way to go.  The
documentation should tell you what you will need to open on your
firewall.  If not, you can try tracing using Ethereal and see what
protocols and ports it uses.

If it does not support NAT-T, then I think your only option is to assign
fixed IP addresses :-(  Perhaps you can isolate an IP subnet they use
(not a bad idea as per the paragraph below) and use the NETMAP target
from pom.

This ability for visitors to attach to their own networks does sound a
bit dangerous.  Is the company management aware that there is the
possibility that someone on the other side of those visiting VPN tunnels
could use the visiting station as an access point to your internal
network? Of course, someone may have addressed that and isolated the
points from which visitors can connect to their own WAN.  Take care -
John

On Wed, 2004-08-25 at 03:24, Roksana Boreli wrote:
> Thanks Jason.
> 
> > enable IKE over TCP on the clients and UDP encapsulation.  
> > this is not a problem with netfilter, but with multiple
> >  IPSec clients behind *any* NAT = device.
> 
> Perhaps some additional info needs to be added about my configuration.
> I need to use standard Cisco Linux clients, as this is for people
> visiting (with their laptops and standard VPN setup for remote access)
> and wanting to get to their (Cisco) server.  In fact, it could be more
> than one ipsec server at some time in the future.  I definitely need to
> use a Cisco VPN gateway (can't use FreeSwan), I cannot have a single vpn
> client from the Linux router device as the requirement is for multiple
> clients behind this device.  The Cisco gateway and Win 2k client can set
> up a connection through a NAT router, we have tried this with a Netgear
> device.  So I thought the issue was similar to pptp vpn pass-through for
> multiple clients (i.e. a patch for the kernel/iptables was the way to
> go), hence the question.  
> 
> Kind regards, Roksana 
> 
> 
> Subject: RE: Multiple IPSEC VPNs through a firewall based on 2.4.2X
> kernel
> Date: Tue, 24 Aug 2004 07:56:33 -0400
> From: "Jason Opperisano" <Jopperisano@alphanumeric.com>
> To: <netfilter@lists.netfilter.org>
> 
> Hi,
> 
> I am trying to set up multiple ipsec VPN clients working behind a Linux
> router with NAT/PAT, based on a 2.4.20 (can be 2.4.22) kernel. I would 
> like to be able to connect a number of Windows (2k or XP) machines to 
> an existing Cisco VPN server.
> 
> Kind regards, Roksana
-- 
John A. Sullivan III
Chief Technology Officer
Nexus Management
+1 207-985-7880
john.sullivan@nexusmgmt.com
---
If you are interested in helping to develop a GPL enterprise class
VPN/Firewall/Security device management console, please visit
http://iscs.sourceforge.net 



  reply	other threads:[~2004-08-25 11:29 UTC|newest]

Thread overview: 12+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2004-08-25  7:24 Multiple IPSEC VPNs through a firewall based on 2.4.2X kernel Roksana Boreli
2004-08-25 11:29 ` John A. Sullivan III [this message]
  -- strict thread matches above, loose matches on Subject: below --
2004-08-25 11:44 Jason Opperisano
2004-08-24 11:56 Jason Opperisano
2004-08-24  5:11 Roksana Boreli
2004-08-24  5:46 ` Ming-Ching Tiew
2004-08-24  7:32   ` Payal Rathod
2004-08-24  7:50     ` Ming-Ching Tiew
2004-08-24  9:31 ` John A. Sullivan III
2004-08-26  9:13   ` Thomas Kirk
2004-08-26 10:39     ` John A. Sullivan III
2004-08-26 14:14       ` Tom Eastep

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1093433311.2034.36.camel@localhost \
    --to=john.sullivan@nexusmgmt.com \
    --cc=Roksana.Boreli@nicta.com.au \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.