Re: VPN Help
From: Dan Bent (dbent_at_comcast.net)
Date: 11/29/03
- Next message: Uwe Dippel: "Re: pf not logging"
- Previous message: erik: "Re: pf not logging"
- In reply to: erik: "Re: VPN Help"
- Next in thread: Dan Bent: "Re: VPN Help"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Date: Sat, 29 Nov 2003 08:33:03 -0500
Thanks for the response. I think you helped me with something else not long
ago.
I'll happily provide details, but I'm not sure what would be useful, and
what might compromise my vpn..
I believe I've followed the examples in the vpn and ipsecadmin man pages,
but the vpn doesn't work. I'm not sure where to begin troubleshooting to
diagnose the problem.
As I understand isakmp, it a method for exchanging authorization codes
dynamically. I would use it, but I don't believe I can configure it to work
with the firewall appliance I have on the office end. That appliance has a
GUI interface for configuring a vpn, and it generated keys, which I have
stored in files on the on the firewall at the ISP end. So, I don't think
authorization keys are a problem, but I can't rule them out either. I don't
get any error messages that I'm aware of, so I really don't know where to
begin, or how to proceed.
"erik" <erik@geenspam.vanwesten.net> wrote in message
news:3fc7fe5c$0$1507$e4fe514c@news.xs4all.nl...
> Dan Bent wrote:
>
> > I'm trying to establish a VPN between my office network, and the
> > network inside my colo closet at my ISP. I'm using OpenBSD pf, and
> > ipsecadmin to set up the VPN on the ISP closet side, and an appliance
> > with a GUI (looks like a GUI front end to PHP scripts) for the
> > firewall on the office side. I've read man pages, how-tos, and
> > tutorials, and I have built a configuration I think
> > out to work, but it doesn't. I'm not sure how to troubleshoot it and
> > identify where the process is breaking down. I'd really appreciate any
> > help I could get.
> >
>
> How can we give help if you don't give details? Anyway, using isakmp is
> a lot easier.
>
> EJ
> --
> Remove the obvious part (including the dot) for my email address.
> http://www.vanwesten.net for examples of ipf and pf.
>
- Next message: Uwe Dippel: "Re: pf not logging"
- Previous message: erik: "Re: pf not logging"
- In reply to: erik: "Re: VPN Help"
- Next in thread: Dan Bent: "Re: VPN Help"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Relevant Pages
|