LARTC
[Top] [All Lists]

Re: [LARTC] VPN Solution

To: lartc@mailman.ds9a.nl
Subject: Re: [LARTC] VPN Solution
From: Grant Taylor <gtaylor@riverviewtech.net>
Date: Tue, 21 Nov 2006 00:15:05 -0600
Delivered-to: sp-com-lists@consult.net
Delivered-to: lartc-list@securepoint.com
Delivered-to: lartc@outpost.ds9a.nl
In-reply-to: <002801c70d35$199a9f60$0101010a@lamachine>
List-archive: <http://mailman.ds9a.nl/pipermail/lartc>
List-help: <mailto:lartc-request@mailman.ds9a.nl?subject=help>
List-id: "Mailinglist of the Linux Advanced Routing &amp; Traffic Control project" <lartc.mailman.ds9a.nl>
List-post: <mailto:lartc@mailman.ds9a.nl>
List-subscribe: <http://mailman.ds9a.nl/cgi-bin/mailman/listinfo/lartc>, <mailto:lartc-request@mailman.ds9a.nl?subject=subscribe>
List-unsubscribe: <http://mailman.ds9a.nl/cgi-bin/mailman/listinfo/lartc>, <mailto:lartc-request@mailman.ds9a.nl?subject=unsubscribe>
References: <002801c70d35$199a9f60$0101010a@lamachine>
Sender: lartc-bounces@mailman.ds9a.nl
User-agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.0.8) Gecko/20061025 Thunderbird/1.5.0.8 Mnenhy/0.7.4.666
On 11/21/06 00:20, Rangi Biddle wrote:
What I want to do is have a VPN (PPTP/IPSEC/CIPE/etc) server, but it must support more than one simultaneous connection.

I currently have a PPTP VPN server setup that has port 1723 and protocol 47 DNAT’d through to the internal IP address of the VPN server and I have not been able to have more than one connection at a time. I am considering setting up the VPN server as a gateway (for lack of a better word) and instead of DNATing the connections through to the internal IP I would setup a DMZ with the VPN server as the only host. My only concern in doing so is that if it does not work what other options do I have besides getting a different connection type such as fibre? I’m trying to do this as cheaply as possible.

Can / will you provide some more information such as what type of client will be connecting to the VPN concentrator?

I believe the 1 concurrent connection you are referring to is a limitation of IPTables match extension for PPTP tunnels. If you put the VPN Concentrator such that it is directly routable you should have better luck.

Beyond PPTP, you can look in to IPSec or SSLTunnel, or any number of other products. However to be able to determine which of the products is best suited to your situation, we need to know more about your situation.



Grant. . . .
_______________________________________________
LARTC mailing list
LARTC@mailman.ds9a.nl
http://mailman.ds9a.nl/cgi-bin/mailman/listinfo/lartc

<Prev in Thread] Current Thread [Next in Thread>