Linux Router (VPN Server) <-- Internet --> Windows XP Pro (VPN Clients)

ZippyDan

Platinum Member
Sep 28, 2001
2,141
1
81
how do i do it?

ive got slackware running on my Linux Router. i want to make it a VPN server (note its only a p233mmx so what kind of security/encryption can it handle?) capable of handling multiple VPN tunnels. i have no idea how to setup my Router as a VPN server, any links/guides/advices?

i know there is pptp and ipsec. advice on which should i use?

the clients will be WinXP Pro. i have no idea how to set them up for VPN connections. any links/guides/advice?

thanks

~Zippy!
 

n0cmonkey

Elite Member
Jun 10, 2001
42,936
1
0
Use IPSEC if you can get IPSEC clients for WinXP. I Think linux 2.6 has KAME in it. Check freshmeat.net for vpn programs (isakmpd?). I'm surprised a google search didn't come up with any information...
 

ZippyDan

Platinum Member
Sep 28, 2001
2,141
1
81
google is full of information. unfortunately so much of it is inapplicable or just plain wrong

doesnt WinXP Pro have built in support for both pptp and ipsec connections (i know theres setup that needs to be done for ipsec)... so why do i need ipsec client software?

~Zippy!
 

n0cmonkey

Elite Member
Jun 10, 2001
42,936
1
0
Originally posted by: ZippyDan
google is full of information. unfortunately so much of it is inapplicable or just plain wrong

doesnt WinXP Pro have built in support for both pptp and ipsec connections (i know theres setup that needs to be done for ipsec)... so why do i need ipsec client software?

~Zippy!

I usually don't use Windows, so I don't know what it has
 

calbars

Member
Dec 21, 2000
29
0
0
Supposing you are running kernel 2.4 on your slackware box, I see 3 solutions (I'm sure there are other if you search).

1) pptp. Run pptpd (www.poptop.org) on your server. Use to docs from poptop to set up the server. The best info on setting up your kernel is from the pptp client project site(http://pptpclient.sourceforge.net/).

Pros: uses the native vpn windows client, simple to configure
Cons: you will need to recompile your kernel to get mppe encryption.

2) ipsec. Run freeswan on your server (www.freeswan.org). But to make interoperate properly with windows' ipsec stack, you should head over to www.freeswan.ca to get a pre-patched version of freeswan with all the goodies. Again, you will need to patch your kernel (unless you run 2.6).

Pros: uses the native windows native ipsec.
Cons: kernel recompile, major PITA to configure and debug. Plus the freeswan project has recently announced that it is commiting hara-kiri.

3) vpn over ssl. Run openvpn on (http://openvpn.sourceforge.net/) you linux machine and your windows machine.

Pros: simple to setup, no kernel recompile.
Cons: You need to install openvpn on windows.


I've used 1 and 2 with success. I've heard good thing about openvpn, might be worth a try.

BTW, I've run 10 ipsec tunnels with light traffic on a P200MHz over a 2mbits link with success. YMMV
 

ZippyDan

Platinum Member
Sep 28, 2001
2,141
1
81
thx for ur post calbars. after hours of research and asking other linux ppl what i should use, i came up with those same 3 options as the best/most popular. nice summary other ppl looking to do the same, take note!

~Zippy!
 

calbars

Member
Dec 21, 2000
29
0
0
your welcome

BTW, one thing that I should have mentioned is that once freeswan is properly configured (this might involved waving dead chickens at your router and invoking $DEITY's name profusely) it is solid as rock.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |