Re: I want to make a Linux IPSEC VPN

From: acva (jil1chr@chartermi.net)
Date: 01/01/02

  • Next message: Ian Jones: "Re: [suse][apache][ssl] https://localhost => error messages"

    From: "acva" <jil1chr@chartermi.net>
    Date: Tue, 1 Jan 2002 10:56:16 -0500
    
    

    I have done this on a 2.2.19 kernel using masq and a patch and perhaps I
    could save you some time wondering around.
    First of all, you have to decide what kind of VPN you want to have.

    Is it direct from one linux box to another?
    If it is and there are no firewalls then you could concider freeswan. Good
    Documentation reading even if you don't use it. www.freeswan.org If there is
    a firewall between the two machines you will have to ensure that firewall
    supports VPN
    Is it going to be a service offered between two firewalls? That is to say if
    you are encrypting on a client and you want to ipmasq and forward thru the
    firewalls you might want to re-compile you firewall kernel to support that.
    I believe the 2.4 kernels already support that. I will have to find the
    patch url. I have it somewhere. You may also find it referenced from the
    freeswan site.
    Do all the machines have fixed ip addresses? If so, good , you can leave
    the tunnel up and not have to worry about starting/stopping . If not, then
    you are in for some negotiation issues.
    Also, if you just want to encrypt traffic (like chat, web content , ftp
    etc....between two boxes, concider openssh.org. Great stuff there.

    <teddymills@hotmail.com> wrote in message
    news:CJ0Y7.9864$Ad5.974557@news20.bellglobal.com...
    >
    > wheres the website to go?
    > What packages shouldI I use?
    >
    >
    >



    Relevant Pages

    • Re: IPFW or pf?
      ... >> I have read the handbook about firewalls, and compiled my kernel ... > The startup scripts support pf, ... the base systems ships with two firewalls? ... firewalls in the handbook, I realized I didn't know much about them. ...
      (freebsd-questions)
    • [Full-Disclosure] RE: remote kernel exploits?
      ... firewalls are based on kernel. ... Because the reason we love open-source is the speed of patching ... Apache, OpenSSH, OpenSSL are all widespread services yet they all have ...
      (Full-Disclosure)
    • Re: Q: How do stealth ports manage to accept a connection?
      ... Firewalls _are_ applications. ... Many filtering software programs are implemented in kernel space. ... Netzwerkgrundlagen anhand Windows lernen zu wollen ist doch wie seine ... Leidenschaft fehlt, das wirklich Wichtige lernt man dabei nicht, und die ...
      (comp.security.firewalls)
    • kernel: dst cache overflow
      ... "kernel: dst cache overflow" problem people have been having... ... The firewalls have just above bare minimal pkgs installs, ... All Red Hat firewalls are running 2.4.25 kernel and the 1 fedora ...
      (Fedora)
    • RE: kernel: dst cache overflow
      ... Conversation: kernel: dst cache overflow ... The firewalls have just above bare minimal pkgs installs, ...
      (Fedora)