All of lore.kernel.org
 help / color / mirror / Atom feed
From: Lists account <lists@jcitc.com>
To: netfilter@lists.netfilter.org
Subject: Multiple client VPN - where to put conntrack?
Date: Mon, 08 Nov 2004 22:43:42 +0000	[thread overview]
Message-ID: <418FF69E.40406@jcitc.com> (raw)

Hi there,

This may be a very stupid question, but I haven't found the information 
anywhere, so here goes - I have a working VPN client-server set-up that 
works through an iptables masquerading NAT configuration but only for 
one client at a time - and I need to expand it. The VPN is:
- Server - running PPTP (poptop) on Redhat 9 connected directly to the 
internet via iptables.
- Client(s) - A small network of workstations (Debian, win2k, mac OSX) 
connected to the internet with ADSL via a Debian router running iptables 
doing NAT. Currently, tunnels are created from the workstations to the 
server through the router and internet successfully, but only one 
machine can connect at a time and I would like to improve on this.

I understand that I need to install PPTP and GRE connection tracking on 
the Debian router...(and here's the silly question...) will the RH9 PPTP 
server need conntrack too?

One further question, the ADSL connection at the client end uses PPPoA 
with LLC - would it be possible for this to stuff up the connection 
tracking or unlikely? And what about PPPoE? Or is it all just completely 
dependent on the ISP?

Thanks,

James




             reply	other threads:[~2004-11-08 22:43 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2004-11-08 22:43 Lists account [this message]
  -- strict thread matches above, loose matches on Subject: below --
2004-11-09  4:10 Multiple client VPN - where to put conntrack? Gary W. Smith
2004-11-10  4:18 Gary W. Smith
2004-11-10 10:59 ` James Cooke

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=418FF69E.40406@jcitc.com \
    --to=lists@jcitc.com \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.