Well, yes that is usually the case - otherwise what would be the 
point of setting up a VPN.  As far as controlling what has access
to what in a LEAF / Shorewall / OpenVPN setup - if it is setup
correctly, you would use the Shorewall rules and policies to 
determine what access the vpn segments have to the "fw"
and to the "loc" network.  

Doug

>>> "chiew yock sang" <[EMAIL PROTECTED]> 05/19/04 04:14AM >>>

Are u trying to say that without vpn, the network segment wouldn't be able 
to ping to another network segment?

thanks!

From: "Doug Hite" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>, <[EMAIL PROTECTED]>
Subject: Re:[leaf-user] vpn capability router
Date: Thu, 06 May 2004 08:04:48 -0500

Well, the most obvious way to tell it is working is that the network
subnets that are being connected can communicate with each other.
Say the local network segment on router A is 192.168.1.0, and on
router B is 192.168.2.0.  If after the VPN is up, and if the Shorewall
rules allow vpn to loc and loc to vpn access on both sides, then you
should be able to comminicate (ping, etc) from one network segment
to another.


Its hard to do these setups in a vacuum.  The best way to do it is to
get a router working - duplicate that to a second router - different
external ip and network segment and confirm that works.  You may
need client on the internal sides of these routers to confirm they
are working correctly.  Once all that is working - add the VPN stuf
to connect the 2 routers.

The clients can be any networked computer that connects to the
local subnet.  Windows, linux, whatever - its used to represent
the clients that will actually be on the networks and using the
VPN link (that would be the point of a VPN after all).

Doug

 >>> "chiew yock sang" <[EMAIL PROTECTED]> 05/06/04 04:29AM >>>
How to know the vpn router is working fine? Do I need to make the 2nd router
before I can determine the router is working fine? Do i need to configure
the client? and how?

Please help me. I'm quite new in leaf, but with your help, I have achieved a
lot.

Thanks for your help and looking forward for your reply


From: "Doug Hite" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Subject: Re:[leaf-user] vpn capability router
Date: Wed, 05 May 2004 09:01:42 -0500

If I were pressed on time, I would do this -

Use Bering 1.2 stock.
Set up 1 router, and get it working.
add the ifconfig and openvpn packages as found here -
http://leaf.sourceforge.net/devel/jnilo/bering/latest/packages/ 
http://lrp.steinkuehler.net/Packages.htm 

add tun.o as found here -
http://download.sourceforge.net/leaf/Bering_1.2_modules_2.4.20.tar.gz 

Set up openvpn using the instructions here and here -
http://leaf.sourceforge.net/doc/guide/buopenvpn.html 
http://www.shorewall.net/OPENVPN.html 

Duplicate to 2nd router, and adjust configuration.

I set up a test vpn using these steps in about an hour.  Its very easy if
you have experience with LEAF.

Things to watch out for -
1) Watch the size on the disk - you will need to remove unused packages
2) In setting up the VPN, use "shorewall clear" and get it working, then
reactivate the firewall and test again.
3) If you follow the shorewall steps exactly - the firewall will not have
access to the vpn, so testing connection from the firewall to the remote
vpn may not be the best place to do it.  Use clients behind the
firewall, or open up access.

Doug

  >I'm currently studying, my lecturer asked me to do a router with VPN
  >capability with floppy disk(s). I have tried a for quite long and still
  >haven get the result. I don't know what has gone wrong.
  >
  >Can anyone show me the proper way to start? I'm willing to start all over
  >again to make sure I'm in the right track.
  >
  >I'm just hoping I can finish this project on time.
  >
  >Thanks.




-------------------------------------------------------
This SF.Net email is sponsored by: Oracle 10g
Get certified on the hottest thing ever to hit the market... Oracle 10g.
Take an Oracle 10g class now, and we'll give you the exam FREE.
http://ads.osdn.com/?ad_id149&alloc_idn66&op=click 
------------------------------------------------------------------------
leaf-user mailing list: [EMAIL PROTECTED] 
https://lists.sourceforge.net/lists/listinfo/leaf-user 
SR FAQ: http://leaf-project.org/pub/doc/docmanager/docid_1891.html 

_________________________________________________________________
Download the latest MSN Messenger http://messenger.msn.com.my 

_________________________________________________________________
Are you in love? Find a date on MSN Personals http://match.msn.com.my/ 



-------------------------------------------------------
This SF.Net email is sponsored by: SourceForge.net Broadband
Sign-up now for SourceForge Broadband and get the fastest
6.0/768 connection for only $19.95/mo for the first 3 months!
http://ads.osdn.com/?ad_id%62&alloc_ida84&op=click
------------------------------------------------------------------------
leaf-user mailing list: [EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/leaf-user
SR FAQ: http://leaf-project.org/pub/doc/docmanager/docid_1891.html

Reply via email to