Re: Intersite VPN



Bryhhh wrote:
<snip>
Or, would the Site B server be presented with an interface on
192.168.16.0/24, and the site B server was left to deal with routing
between the two? If this was the case though, how would I route back
in the other direction? Surely the site A server must have a virtual
interface of some description too?

Usually we use ipsec tunnels between sites. With an ipsec tunnel you
don't have that .18 network needed. I'm not a site-to-site ssl-vpn
expert, but I have already configured client-ssl-vpn's in a not to
distant past.
Depending on your distro you will have more or less tutorials with the
installation and configuration instructions.
Don't forget you'll have to generate SSL certificates for both sides.
(self-signed is perfect)

btw: You'll probably want a routed tunnel.

A good place to start is: http://openvpn.net/howto.html
Also look at your favorite encyclopedia: http://en.wikipedia.org/wiki/OpenVPN

But remember this: The advantage of OpenVPN is you can do many many
things with it. And the disadvante of OpenVPN is that you can do many
many things with it.

You'll probably really understand this after playing a few hours with it
while digging the net for good tuts.


--
mailto:christophe@xxxxxxxxxxxxx
http://christophe.vandeplas.com
.



Relevant Pages

  • Re: Probleme mit openvpn
    ... Irgendwo muss man dem Interface doch eine IP zuodrnen ... ... Ich habe openvpn durch /etc/init.d/openvpn start gestartet und er meldet ... # TCP or UDP server? ... # and each of the client certificates. ...
    (de.comp.os.unix.linux.misc)
  • Re: [Fedora] Re: VPN
    ... I'll share my working OpenVPN server config with you. ... I have mine set to use PAM authentication (meaning they'd need an account on your F10 server, LDAP or otherwise) and ignores client certificates, which could be bad, but it's just me and it's passworded with the user account access. ... # the firewall for the TUN/TAP interface. ...
    (Fedora)
  • fc5 + openvpn + not routing across the tunnel..
    ... I have configured openvpn in my lab ... bad source address from client, ... the server is configured as follows ... # This config item must be copied to ...
    (Fedora)
  • Re: SonicWall vs. WatchGuard Vergleich
    ... Admin bin, habe ich in anderen Bereichen auch schon mitbekommen, dass ... Bei openVPN nimmst Du Dir einen IPcop plus Zerina ... 20 Mann Firma wegen Administrativen Aufwand nicht lohnt, ... Natürlich ist es riskanter einen SMTP server zu fahren. ...
    (de.comp.security.firewall)
  • Re: DMZ and AD
    ... and Exchange hosts assuming that the problem of IPSec tunnels to ... Exchange clusters is now recommended) with the intent of requiring fewer ... allow the FE server the communications with the Exchange and Active ...
    (microsoft.public.windows.server.active_directory)