Networking Forums

Networking Forums > Computer Networking > Linux Networking > Can't talk between VPN'd client and Linux server.

Reply
Thread Tools Display Modes

Can't talk between VPN'd client and Linux server.

 
 
thenighthawk@gmail.com
Guest
Posts: n/a

 
      06-28-2005, 03:22 PM
Hello,

I have two Linux servers running the latest AS Redhat.

My VPN server is a basic Windows 2003 machine, supporting pptp, (I
don't have certificate installed yet for l2tp)

Client machine is Windows XP.

All patches/updates have been applied to all machines.

These machines are all running on the same departmental level subnet.

Client attaches to VPN without issue, makes pptp connection, and I can
see all windows based resources on the local network. I can ping other
windows machines, I can connect to shares, I can access web pages which
are ordinarily blocked by the firewall...

With the exception of my two Linux machines.

>From my VPN machine, I can ping/connect to the web services/ssh to the

two linux machines, I can do the same from any local windows client.
>From the linux machine, I can ping all the local windows

servers/clients.

However, I cannot ping the VPN client from the linux machines (I can
ping, and as I write this, I am connected to the VPN client via remote
desktop, from this local machine), nor can I pull up the web page
hosted on the linux machine.

Now here it gets even worse.

If I connect to the main campus VPN connection, then I CAN see the web
page hosted on the linux machines (I cannot ping though, as ICMP is
blocked at our department firewall...)

Any help would be greatly appreciated!!

 
Reply With Quote
 
 
 
 
Dusty Harper {MS}
Guest
Posts: n/a

 
      06-28-2005, 07:09 PM
This forum is for Windows Firewall Discussion. You may wish to post this to
microsoft.public.win2000.networking.

And to try to be of help, you may want to sniff on the Linux servers, see
if they are even getting the packets from the VPN client. Your entire setup
is not clear, and you may be experiencing a simple route issue ( if the
Linux boxes don't know where to send packets to the VPN client's subnet
etc. ) A sniff of a simple PING should help you determine where to look.
Post back in the appropriate forum and I'll try to help more.

--
--
Dusty Harper
Microsoft Corporation
----------------------------------------------------------------------------
This posting is provided "AS IS", with NO warranties and confers NO rights
----------------------------------------------------------------------------

<(E-Mail Removed)> wrote in message
news:(E-Mail Removed) ups.com...
> Hello,
>
> I have two Linux servers running the latest AS Redhat.
>
> My VPN server is a basic Windows 2003 machine, supporting pptp, (I
> don't have certificate installed yet for l2tp)
>
> Client machine is Windows XP.
>
> All patches/updates have been applied to all machines.
>
> These machines are all running on the same departmental level subnet.
>
> Client attaches to VPN without issue, makes pptp connection, and I can
> see all windows based resources on the local network. I can ping other
> windows machines, I can connect to shares, I can access web pages which
> are ordinarily blocked by the firewall...
>
> With the exception of my two Linux machines.
>
>>From my VPN machine, I can ping/connect to the web services/ssh to the

> two linux machines, I can do the same from any local windows client.
>>From the linux machine, I can ping all the local windows

> servers/clients.
>
> However, I cannot ping the VPN client from the linux machines (I can
> ping, and as I write this, I am connected to the VPN client via remote
> desktop, from this local machine), nor can I pull up the web page
> hosted on the linux machine.
>
> Now here it gets even worse.
>
> If I connect to the main campus VPN connection, then I CAN see the web
> page hosted on the linux machines (I cannot ping though, as ICMP is
> blocked at our department firewall...)
>
> Any help would be greatly appreciated!!
>



 
Reply With Quote
 
thenighthawk@gmail.com
Guest
Posts: n/a

 
      06-28-2005, 07:25 PM
Unfortunately there's no routing being done by the Linux boxes at all,
they are on the private side of the VPN Server's network (both
physically and logically).

 
Reply With Quote
 
Dusty Harper {MS}
Guest
Posts: n/a

 
      06-29-2005, 11:07 PM
They still need to perform a route lookup to see which router to send the
traffic ( unless the VPN client is handed an IP on the locl subnet )


--
--
Dusty Harper
Microsoft Corporation
----------------------------------------------------------------------------
This posting is provided "AS IS", with NO warranties and confers NO rights
----------------------------------------------------------------------------

<(E-Mail Removed)> wrote in message
news:(E-Mail Removed) oups.com...
> Unfortunately there's no routing being done by the Linux boxes at all,
> they are on the private side of the VPN Server's network (both
> physically and logically).
>



 
Reply With Quote
 
thenighthawk@gmail.com
Guest
Posts: n/a

 
      06-30-2005, 02:23 PM
That is the case, the VPN client gets an address from within the local
subnet.

Once the VPN client is connected, I can remote desktop to the client
using the local address, the client can see all my windows boxes, but
these two linux boxes are invisible, I can't ping, ssh, ftp, or pull up
the web page, whether I try to do so using the IP address of the linux
box, or the name.

I am at such a loss as to why all the windows machines are visible, but
the linux are not.



Dusty Harper {MS} wrote:
> They still need to perform a route lookup to see which router to send the
> traffic ( unless the VPN client is handed an IP on the locl subnet )
>
>
> --
> --
> Dusty Harper
> Microsoft Corporation
> ----------------------------------------------------------------------------
> This posting is provided "AS IS", with NO warranties and confers NO rights
> ----------------------------------------------------------------------------
>
> <(E-Mail Removed)> wrote in message
> news:(E-Mail Removed) oups.com...
> > Unfortunately there's no routing being done by the Linux boxes at all,
> > they are on the private side of the VPN Server's network (both
> > physically and logically).
> >


 
Reply With Quote
 
Mike Drechsler - SPAM PROTECTED EMAIL
Guest
Posts: n/a

 
      06-30-2005, 03:05 PM
(E-Mail Removed) wrote:
> That is the case, the VPN client gets an address from within the local
> subnet.
>
> Once the VPN client is connected, I can remote desktop to the client
> using the local address, the client can see all my windows boxes, but
> these two linux boxes are invisible, I can't ping, ssh, ftp, or pull up
> the web page, whether I try to do so using the IP address of the linux
> box, or the name.
>
> I am at such a loss as to why all the windows machines are visible, but
> the linux are not.
>
>
>
> Dusty Harper {MS} wrote:
>
>>They still need to perform a route lookup to see which router to send the
>>traffic ( unless the VPN client is handed an IP on the locl subnet )
>>
>>
>>--
>>--
>>Dusty Harper
>>Microsoft Corporation
>>----------------------------------------------------------------------------
>>This posting is provided "AS IS", with NO warranties and confers NO rights
>>----------------------------------------------------------------------------
>>
>><(E-Mail Removed)> wrote in message
>>news:(E-Mail Removed) groups.com...
>>
>>>Unfortunately there's no routing being done by the Linux boxes at all,
>>>they are on the private side of the VPN Server's network (both
>>>physically and logically).


What does the arp table on the linux box look like? The arp address of
the VPN clients IP should resolve to the same ethernet id as the VPN
gateway/server. Also what does the arp table on the client look like.
Does it get the ethernet id of the linux box. If you find arp problems,
does creating a static entry with the ethernet mac address of the remote
system help?

--
WARNING! Email address has been altered for spam resistance.
Please remove the -deletethispart-. section before replying directly.
Mike Drechsler (mike-newsgroup@-deletethispart-.upcraft.com)
 
Reply With Quote
 
thenighthawk@gmail.com
Guest
Posts: n/a

 
      06-30-2005, 03:37 PM

Mike, you were on the right track!

Monitoring the ARP caches, the Linux boxes were trying to communicate
with the public side IP address (also on my local subnet, as I am not
able to do NAT and private addressing here).

I used the default filter to block all but VPN tunnel traffic on the
public address. By adding my local subnet in the "allow" for incoming
packets to the public side address, all was well.

Thanks!!


Mike Drechsler - SPAM PROTECTED EMAIL wrote:
> (E-Mail Removed) wrote:
> > That is the case, the VPN client gets an address from within the local
> > subnet.
> >
> > Once the VPN client is connected, I can remote desktop to the client
> > using the local address, the client can see all my windows boxes, but
> > these two linux boxes are invisible, I can't ping, ssh, ftp, or pull up
> > the web page, whether I try to do so using the IP address of the linux
> > box, or the name.
> >
> > I am at such a loss as to why all the windows machines are visible, but
> > the linux are not.
> >
> >
> >
> > Dusty Harper {MS} wrote:
> >
> >>They still need to perform a route lookup to see which router to send the
> >>traffic ( unless the VPN client is handed an IP on the locl subnet )
> >>
> >>
> >>--
> >>--
> >>Dusty Harper
> >>Microsoft Corporation
> >>----------------------------------------------------------------------------
> >>This posting is provided "AS IS", with NO warranties and confers NO rights
> >>----------------------------------------------------------------------------
> >>
> >><(E-Mail Removed)> wrote in message
> >>news:(E-Mail Removed) groups.com...
> >>
> >>>Unfortunately there's no routing being done by the Linux boxes at all,
> >>>they are on the private side of the VPN Server's network (both
> >>>physically and logically).

>
> What does the arp table on the linux box look like? The arp address of
> the VPN clients IP should resolve to the same ethernet id as the VPN
> gateway/server. Also what does the arp table on the client look like.
> Does it get the ethernet id of the linux box. If you find arp problems,
> does creating a static entry with the ethernet mac address of the remote
> system help?
>
> --
> WARNING! Email address has been altered for spam resistance.
> Please remove the -deletethispart-. section before replying directly.
> Mike Drechsler (mike-newsgroup@-deletethispart-.upcraft.com)


 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Talk Talk Business WWW upload server? Andy Blanchard Broadband 8 02-08-2011 08:26 PM
Linux VPN server and client susikaufmann2003@hotmail.com Linux Networking 4 12-01-2007 12:59 PM
IS Talk Talk email server down?? Dave P Broadband 2 08-22-2005 08:11 PM
NFS, Linux client, OSX server jb_is_not@home.yet Linux Networking 8 09-13-2004 04:41 PM
Trouble Installing Linux/Cisco VPN Client Has anyone had trouble compiling the linux cisco vpn client? Here is the output of the install script: # uname -rviosm Linux 2.4.22-1.2188.nptl #1 Wed Apr 21 20:19:18 EDT 2004 x86_64 x86_64 GNU/Linux JSH Linux Networking 4 07-02-2004 12:48 PM



1 2 3 4 5 6 7 8 9 10 11