Networking Forums

Networking Forums > Computer Networking > Linux Networking > VPN Server not as a gateway.

Reply
Thread Tools Display Modes

VPN Server not as a gateway.

 
 
toxicated101
Guest
Posts: n/a

 
      06-15-2006, 08:48 AM
Hi

Is there any way to put a linux box with openswan or freeswan on a
network and having it behave as a vpn server without having it as a
gateway. Most vpn servers I have seen act as a gateway, have 2
interfaces and sit between the outside line and the internal network.
What I want is a vpn server I can just attach to the lan switch with
one ethernet jack. Basically I want it to be more of a mail server
install than a gateway/ firewall install. I already have a hardware
firewall between the wan and the lan, but the vpn on it is rubbish and
refusses to work correctly with any other vpn clients. So If I can
place a box onto the lan which will then replace the vpn server on the
firewall, without it being a point of failure for the entire network,
that would be ideal. If the vpn server dies , you loose vpn , rather
than if the vpn gateway fails you loose the network.

thanks

Matt

 
Reply With Quote
 
 
 
 
Dave {Reply Address In.sig}
Guest
Posts: n/a

 
      06-15-2006, 09:20 AM
toxicated101 wrote:
> Hi
>
> Is there any way to put a linux box with openswan or freeswan on a
> network and having it behave as a vpn server without having it as a
> gateway. Most vpn servers I have seen act as a gateway, have 2
> interfaces and sit between the outside line and the internal network.
> What I want is a vpn server I can just attach to the lan switch with
> one ethernet jack. Basically I want it to be more of a mail server
> install than a gateway/ firewall install. I already have a hardware
> firewall between the wan and the lan, but the vpn on it is rubbish and
> refusses to work correctly with any other vpn clients. So If I can
> place a box onto the lan which will then replace the vpn server on the
> firewall, without it being a point of failure for the entire network,
> that would be ideal. If the vpn server dies , you loose vpn , rather
> than if the vpn gateway fails you loose the network.
>

Isn't that just a case of port-forwarding the VPN port through the
firewall box to the machine inside? That's what I've got set up here, a
pptp server on a machine that is patched through the firewall machine.

--
Dave
mail da (E-Mail Removed) (without the space)
http://www.llondel.org
So many gadgets, so little time
 
Reply With Quote
 
toxicated101
Guest
Posts: n/a

 
      06-15-2006, 09:53 AM
Hi Dave

Possibly, the only problem I see is that you would have to put some
static links onto the firewall to tell it to send any traffic
designated to a internal ip subnet (on the remote side) to the vpn
machine. I just wanted to ask , I haven't seen it done and didn't want
to waste my day if its not possible.

Thanks

Matt

Dave {Reply Address In.sig} wrote:
> toxicated101 wrote:
> > Hi
> >
> > Is there any way to put a linux box with openswan or freeswan on a
> > network and having it behave as a vpn server without having it as a
> > gateway. Most vpn servers I have seen act as a gateway, have 2
> > interfaces and sit between the outside line and the internal network.
> > What I want is a vpn server I can just attach to the lan switch with
> > one ethernet jack. Basically I want it to be more of a mail server
> > install than a gateway/ firewall install. I already have a hardware
> > firewall between the wan and the lan, but the vpn on it is rubbish and
> > refusses to work correctly with any other vpn clients. So If I can
> > place a box onto the lan which will then replace the vpn server on the
> > firewall, without it being a point of failure for the entire network,
> > that would be ideal. If the vpn server dies , you loose vpn , rather
> > than if the vpn gateway fails you loose the network.
> >

> Isn't that just a case of port-forwarding the VPN port through the
> firewall box to the machine inside? That's what I've got set up here, a
> pptp server on a machine that is patched through the firewall machine.
>
> --
> Dave
> mail da (E-Mail Removed) (without the space)
> http://www.llondel.org
> So many gadgets, so little time


 
Reply With Quote
 
Frank Sweetser
Guest
Posts: n/a

 
      06-15-2006, 01:21 PM
toxicated101 <(E-Mail Removed)> wrote:
> Hi
>
> Is there any way to put a linux box with openswan or freeswan on a
> network and having it behave as a vpn server without having it as a
> gateway. Most vpn servers I have seen act as a gateway, have 2
> interfaces and sit between the outside line and the internal network.
> What I want is a vpn server I can just attach to the lan switch with
> one ethernet jack. Basically I want it to be more of a mail server


Search around for what's called a "one armed" vpn configuration.

--
Frank Sweetser fs at wpi.edu | For every problem, there is a solution that
WPI Network Engineer | is simple, elegant, and wrong. - HL Mencken
GPG fingerprint = 6174 1257 129E 0D21 D8D4 E8A3 8E39 29E3 E2E8 8CEC
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
win 2k3 SBS server changing the STATIC gateway address of a win 2k Adv server, Why? MMJII Windows Networking 1 01-08-2007 07:08 PM
windows server 2003 gateway and dhcp server on the same computer boiseneon Windows Networking 3 02-22-2006 05:48 AM
2 gateway's one server Cjack Windows Networking 3 11-03-2005 09:36 AM
Gateway server problems Ilya81 Windows Networking 0 09-06-2005 12:51 PM
Cant see linux server through gateway. Alan Linux Networking 5 09-17-2003 12:07 AM



1 2 3 4 5 6 7 8 9 10 11