<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://port25.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Technical Analysis: Linux VPN &amp;amp; How-To</title><link>http://port25.technet.com/archive/2007/03/09/technical-analysis-linux-vpn-how-to.aspx</link><description>In our continuing series of papers describing both the research undertaken by the Open Source Software Lab, and technical tips, here is the latest networking configuration technical analysis. Abstract: This document provides the reader with an analysis</description><dc:language>en</dc:language><generator>CommunityServer 2007.1 (Build: 40109.1145)</generator><item><title>re: Technical Analysis: Linux VPN &amp; How-To</title><link>http://port25.technet.com/archive/2007/03/09/technical-analysis-linux-vpn-how-to.aspx#27741</link><pubDate>Tue, 15 Sep 2009 21:34:59 GMT</pubDate><guid isPermaLink="false">af7480c4-26b7-468d-87b0-2acebabb473d:27741</guid><dc:creator>cybul</dc:creator><description>&lt;p&gt;ok&lt;/p&gt;
&lt;img src="http://port25.technet.com/aggbug.aspx?PostID=27741" width="1" height="1"&gt;</description></item><item><title>re: Technical Analysis: Linux VPN &amp; How-To</title><link>http://port25.technet.com/archive/2007/03/09/technical-analysis-linux-vpn-how-to.aspx#27740</link><pubDate>Tue, 15 Sep 2009 21:31:04 GMT</pubDate><guid isPermaLink="false">af7480c4-26b7-468d-87b0-2acebabb473d:27740</guid><dc:creator>cybul</dc:creator><description>&lt;p&gt;ok&lt;/p&gt;
&lt;img src="http://port25.technet.com/aggbug.aspx?PostID=27740" width="1" height="1"&gt;</description></item><item><title>re: Technical Analysis: Linux VPN &amp; How-To</title><link>http://port25.technet.com/archive/2007/03/09/technical-analysis-linux-vpn-how-to.aspx#27340</link><pubDate>Tue, 18 Aug 2009 04:50:11 GMT</pubDate><guid isPermaLink="false">af7480c4-26b7-468d-87b0-2acebabb473d:27340</guid><dc:creator>Gl199909</dc:creator><description>&lt;p&gt;858585&lt;/p&gt;
&lt;img src="http://port25.technet.com/aggbug.aspx?PostID=27340" width="1" height="1"&gt;</description></item><item><title>re: Technical Analysis: Linux VPN &amp; How-To</title><link>http://port25.technet.com/archive/2007/03/09/technical-analysis-linux-vpn-how-to.aspx#27339</link><pubDate>Tue, 18 Aug 2009 04:49:54 GMT</pubDate><guid isPermaLink="false">af7480c4-26b7-468d-87b0-2acebabb473d:27339</guid><dc:creator>Gl199909</dc:creator><description>&lt;p&gt;ASERDTFYGUHIOOYTRTFYGUHIOK&lt;/p&gt;
&lt;img src="http://port25.technet.com/aggbug.aspx?PostID=27339" width="1" height="1"&gt;</description></item><item><title>riverbed wan acceleration</title><link>http://port25.technet.com/archive/2007/03/09/technical-analysis-linux-vpn-how-to.aspx#21602</link><pubDate>Tue, 04 Nov 2008 10:41:20 GMT</pubDate><guid isPermaLink="false">af7480c4-26b7-468d-87b0-2acebabb473d:21602</guid><dc:creator>riverbed wan acceleration</dc:creator><description>&lt;p&gt;I’ ve had occasion to try out taksi, it worked well for GDI capture, but for Direct3D capture on the engine I used it failed in CTaksiDX9:: GetFrame during GetRenderTargetData. I’ ve found a solution by disabling the avi feature (I didn’ t need it) and&lt;/p&gt;
&lt;img src="http://port25.technet.com/aggbug.aspx?PostID=21602" width="1" height="1"&gt;</description></item><item><title>Windows Vista Beta/Linux IPsec Interop Testing</title><link>http://port25.technet.com/archive/2007/03/09/technical-analysis-linux-vpn-how-to.aspx#3875</link><pubDate>Thu, 10 May 2007 00:33:58 GMT</pubDate><guid isPermaLink="false">af7480c4-26b7-468d-87b0-2acebabb473d:3875</guid><dc:creator>Port 25</dc:creator><description>&lt;p&gt;This document provides an overview of LInux IPsec solutions as well as detailed discussions on configuring IPsec-Tools for interoperability scenarios between Red Hat Linux Enterprise 4 and Windows Vista Ultimate Beta.&lt;/p&gt;
&lt;img src="http://port25.technet.com/aggbug.aspx?PostID=3875" width="1" height="1"&gt;</description></item><item><title>OpenVPN deserves mentioning</title><link>http://port25.technet.com/archive/2007/03/09/technical-analysis-linux-vpn-how-to.aspx#3857</link><pubDate>Thu, 03 May 2007 13:34:37 GMT</pubDate><guid isPermaLink="false">af7480c4-26b7-468d-87b0-2acebabb473d:3857</guid><dc:creator>Rune Kock</dc:creator><description>&lt;p&gt;IPSec is usually a pain to set up. So if you just need any kind of VPN, I've found that OpenVPN is a lot easier to work with. &amp;nbsp;It is available for Windows, Linux and many other systems.&lt;/p&gt;
&lt;img src="http://port25.technet.com/aggbug.aspx?PostID=3857" width="1" height="1"&gt;</description></item><item><title>re: Technical Analysis: Linux VPN &amp; How-To</title><link>http://port25.technet.com/archive/2007/03/09/technical-analysis-linux-vpn-how-to.aspx#3626</link><pubDate>Sat, 10 Mar 2007 23:35:39 GMT</pubDate><guid isPermaLink="false">af7480c4-26b7-468d-87b0-2acebabb473d:3626</guid><dc:creator>einhverfr</dc:creator><description>&lt;p&gt;Just some supplimental info from my experience that people might find helpful.&lt;/p&gt;
&lt;p&gt;I have build site-to-site Linux vpn appliances before. &amp;nbsp;I have generally used OpenS/WAN and, optionally, iptools. &amp;nbsp; Generally, I used pre-shared public/private rsa key pairs (which opens/wan supports w/o X.509). &amp;nbsp;I am not sure whether the default ipsec-tools supports pre-shared or opportunistic encryption (looking up the public key in a DNS TXT record).&lt;/p&gt;
&lt;p&gt;However, there is one other configuration which can be helpful in a tunnelled environment: &amp;nbsp;GRE inside of IPSec. &amp;nbsp;With this protocol, it is possible to forward *any* network traffic whether or not it is TCP/IP based. One can bring a legacy workstation using NetBEUI, SNA, IPX, or even raw ethernet at a remote location into the company network for example. &amp;nbsp;This configuration however has extra overhead similar to the use of L2TP to encapsulate IPSec.&lt;/p&gt;
&lt;p&gt;I have often seen an assymetric routing problem in VPN setups. &amp;nbsp;The basic issue is that if you don't have the routing tables set up properly on both sides, it is possible to have reply packets (such as TCP ack's or DNS responses) routed back in the clear across the internet connection. &amp;nbsp;When this happens, the connecting program will not see the replies and the connections will fail. &amp;nbsp;This is probably the most common problem with site-to-site setups and is the first thing to check on both sides of the connection. &amp;nbsp;I would say that it accounts for about 90% of the network problems I have seen on site to site links (the other 10% tends to be dns, address, and key management). &amp;nbsp;Unfortunately these can be caused by NATs, routers, routing rules, and the like. &amp;nbsp;If the VPN appliance is not also the main gateway, it can even be difficult or impossible to fix (depending on what the gateway's capabilities are) without upgrading to a better router.&lt;/p&gt;
&lt;p&gt;Finally I wanted to note that in Linux, VPN tunnels are listed as network interfaces. &amp;nbsp;They show up on ifconfig, and can have routing entries associated with them. &amp;nbsp;These include IPsec tunnels, GRE tunnels, IPoIP, and the like. &amp;nbsp;This can also cause a packet to transverse the Netfilter rules multiple times. &amp;nbsp;For example, a TCP/IP packet coming in via a GRE/IPSec tunnel would transverse first via the IPSec packet coming in from the network interface, then as the GRE packet coming in from the IPSec tunnel interface, then finally as the unencapsulated packet coming from the GRE tunnel interface.&lt;/p&gt;
&lt;p&gt;Anyway, I hope this helps.&lt;/p&gt;
&lt;img src="http://port25.technet.com/aggbug.aspx?PostID=3626" width="1" height="1"&gt;</description></item></channel></rss>