LARTC
[Top] [All Lists]

[LARTC] RE: VPN Solution

To: <lartc@mailman.ds9a.nl>
Subject: [LARTC] RE: VPN Solution
From: "Rangi Biddle" <rangi@ngen.net.nz>
Date: Tue, 21 Nov 2006 21:36:49 +1300
Delivered-to: sp-com-lists@consult.net
Delivered-to: lartc-list@securepoint.com
Delivered-to: lartc@outpost.ds9a.nl
List-archive: <http://mailman.ds9a.nl/pipermail/lartc>
List-help: <mailto:lartc-request@mailman.ds9a.nl?subject=help>
List-id: "Mailinglist of the Linux Advanced Routing &amp; Traffic Control project" <lartc.mailman.ds9a.nl>
List-post: <mailto:lartc@mailman.ds9a.nl>
List-subscribe: <http://mailman.ds9a.nl/cgi-bin/mailman/listinfo/lartc>, <mailto:lartc-request@mailman.ds9a.nl?subject=subscribe>
List-unsubscribe: <http://mailman.ds9a.nl/cgi-bin/mailman/listinfo/lartc>, <mailto:lartc-request@mailman.ds9a.nl?subject=unsubscribe>
Sender: lartc-bounces@mailman.ds9a.nl
Thread-index: AccNSC+Lvko/u65qRrKXpzvR43PZuQ==

> Hum.  Is your DSL modem built in to the router you are using, or could you supplant your router with a / your Linux box? 

> If you can put your Linux box directly on the internet, then your VPN concentrator will (inherently) be directly on the net too.

 

Unfortunately my router is combined with the DSL modem effectively a single CPE.

 

> I believe the limitation, which may have been patched and with out being aware of it as I don't use PPTP (yet), is in the helper module for

> connection tracking for PPTP.  I would have to refresh my self on the PPTP protocol and it's interaction with IPTables.  I suggest you do some more

> reading on the mailing list as well as on NetFilter.org to see if you can find out something else.

 

I have just come across some information that says that the connection tracking support for PPTP connections in particular is now part of the mainstream kernel ( >= 2.6.14 ).  I am currently downloading version 2.6.18-3 and will let you know how it goes.

 

PS. I’m using CentOS which probably isn’t the best choice for hacking things to pieces – guess that serves me right.  I believe debian (Sarge) has support for pptp_conntrack in it already so I might give that a go as well.

 

If you’re interested I am more than happy to discuss this matter off the mailing lists, but perhaps may serve a better purpose by being on the lists for future reference for others.

_______________________________________________
LARTC mailing list
LARTC@mailman.ds9a.nl
http://mailman.ds9a.nl/cgi-bin/mailman/listinfo/lartc
<Prev in Thread] Current Thread [Next in Thread>