Re: VPN, NAT and LDAP or FTP

From: /dev/rob0 (rob0_at_gmx.co.uk)
Date: 08/13/03


Date: Wed, 13 Aug 2003 07:05:00 -0700


[2nd attempt - sorry if a duplicate comes through]
[comp.dcom.vpn dropped from this attempt, and may be threaded wrong]

René Matthäi wrote:
> I read information about Super FreeS/WAN, CIPE, OpenVPN (vtun) and so

OpenVPN != vtun ... but it uses the universal tun/tap driver.

> on. But I cannot see if there is at all a possibility to have VPN
> between to NATed Intranets, each VPN GW situated behind the FWs - and

I have 4 sites linked in such a way using OpenVPN. If both endpoints
have relatively static IP's and stateful firewalls, no port forwarding
is needed. Each side knows where (IP/port) to send its tunnel packets,
and the firewalls see it as an established connection.

If either endpoint has a dynamic IP, the *other* side needs to forward
the single UDP port to the internal VPN host.

> providing the capability of FTP or LDAP traffic between the intranets.

FTP works. I haven't tried LDAP so I don't know, but it should work
AFAIK. I've successfully used ssh, NFS, SMB, NTP and others.

-- 
  /dev/rob0 - preferred_email=i$((28*28+28))@softhome.net
  or put "not-spam" or "/dev/rob0" in Subject header to reply


Relevant Pages

  • Re: VPN, NAT and LDAP or FTP
    ... > I read information about Super FreeS/WAN, CIPE, OpenVPN and so ... If both endpoints ... have relatively static IP's and stateful firewalls, ... the single UDP port to the internal VPN host. ...
    (comp.os.linux.networking)
  • Re: VPN, NAT and LDAP or FTP
    ... > I read information about Super FreeS/WAN, CIPE, OpenVPN and so ... OpenVPN!= vtun ... ... have relatively static IP's and stateful firewalls, ... the single UDP port to the internal VPN host. ...
    (comp.os.linux.networking)
  • Re: VPN, NAT and LDAP or FTP
    ... > I read information about Super FreeS/WAN, CIPE, OpenVPN and so ... OpenVPN!= vtun ... ... have relatively static IP's and stateful firewalls, ... the single UDP port to the internal VPN host. ...
    (comp.os.linux.security)
  • Re: VPN to Linux server behind NAT router from XP Home?
    ... Steve Horsley wrote: ... > I have done this with openvpn. ... > is creating the certificates. ... It all uses a single UDP port and ...
    (comp.os.linux.networking)

Quantcast