Firewall + VPN SERVER

Lennart Sorensen lsorense-1wCw9BSqJbv44Nm34jS7GywD8/FfD2ys at public.gmane.org
Sat Mar 27 14:46:12 UTC 2004


On Mon, Mar 22, 2004 at 09:40:30PM -0500, Paul Kozlenko wrote:
> Can anybody on this list recommend a firewall distro that also contains
> a vpn SERVER.
> 
> Looked at Smoothwall and did not see anything that would suggest that it
> could be a server. It can make a connection between 2 smoothwall boxes.
> 
> I was looking for something where I could have a client on a Window$ PC
> establish the vpn connection to a firewall.
> 
> One point however. The firewall is on Rogers and therefore has a
> semi-fixed IP.  But no control over public DNS as it seems is required
> by freeswan (unless I am mistaken).

Only required for oportunistic encryption tunnels.  If you use preshared
keys, or prespecified rsa signatures, it should not require any DNS
info.  The client will need to know the server ip, but with rsa keys it
should be possible to have the signature of the client tell the server
who is connected.  At least that's what I get from the docs.  I ahve
only ever done freeswan with preshared keys between static IPs.

> The simpler the config (or the better the help) the better.
> 
> Any help or feedback would be welcome.

I think freeswan (IPsec) is what you want.

Lennart Sorensen
--
The Toronto Linux Users Group.      Meetings: http://tlug.ss.org
TLUG requests: Linux topics, No HTML, wrap text below 80 columns
How to UNSUBSCRIBE: http://tlug.ss.org/subscribe.shtml





More information about the Legacy mailing list