Re: VPN, NAT and LDAP or FTP

From: /dev/rob0 (rob0_at_gmx.co.uk)
Date: 08/13/03

  • Next message: Jem Berkes: "Is this the famous RPC exploit packet?"
    Date: Tue, 12 Aug 2003 20:41:52 -0700
    
    

    In article <bhambq$m8j$04$1@news.t-online.com>, René Matthäi wrote:
    > I read information about Super FreeS/WAN, CIPE, OpenVPN (vtun) and so

    OpenVPN != vtun ... but it uses the universal tun/tap driver.

    > on. But I cannot see if there is at all a possibility to have VPN
    > between to NATed Intranets, each VPN GW situated behind the FWs - and

    I have 4 sites linked in such a way using OpenVPN. If both endpoints
    have relatively static IP's and stateful firewalls, no port forwarding
    is needed. Each side knows where (IP/port) to send its tunnel packets,
    and the firewalls see it as an established connection.

    If either endpoint has a dynamic IP, the *other* side needs to forward
    the single UDP port to the internal VPN host.

    > providing the capability of FTP or LDAP traffic between the intranets.

    FTP works. I haven't tried LDAP so I don't know, but it should work
    AFAIK. I've successfully used ssh, NFS, SMB, NTP and others.

    -- 
      /dev/rob0 - preferred_email=i$((28*28+28))@softhome.net
      or put "not-spam" or "/dev/rob0" in Subject header to reply
    

  • Next message: Jem Berkes: "Is this the famous RPC exploit packet?"

    Relevant Pages

    • Re: VPN, NAT and LDAP or FTP
      ... > I read information about Super FreeS/WAN, CIPE, OpenVPN and so ... If both endpoints ... have relatively static IP's and stateful firewalls, ... the single UDP port to the internal VPN host. ...
      (comp.os.linux.networking)
    • Re: VPN, NAT and LDAP or FTP
      ... > I read information about Super FreeS/WAN, CIPE, OpenVPN and so ... If both endpoints ... have relatively static IP's and stateful firewalls, ... the single UDP port to the internal VPN host. ...
      (comp.os.linux.security)
    • Re: SSL VPN
      ... On 7/13/05, Edmond Chow wrote: ... > OpenVPN but wanted some guidance on this product versus some other products ... Edmond, a long time ago I've used VTUN, which was quite good. ... it to ipsec, vtun, pptp, etc) nowadays. ...
      (Security-Basics)
    • Re: VPN, NAT and LDAP or FTP
      ... > I read information about Super FreeS/WAN, CIPE, OpenVPN and so ... OpenVPN!= vtun ... ... have relatively static IP's and stateful firewalls, ... the single UDP port to the internal VPN host. ...
      (comp.os.linux.networking)
    • Re: a bit OT - VPN+Windows
      ... One of the nice things about this solution is you can customize the OpenVPN GUI. ... There are various IPSEC solutions but you run into a client issue in a lot of cases for the Windows side. ... i used VPN's many times but always with unix on both sides and used vtun which works great. ...
      (freebsd-questions)