OpenBSD VPN server with active directory auth

From: Ghazan Haider (ghazan_at_ghazan.haider.name)
Date: 03/28/04


Date: 27 Mar 2004 17:55:16 -0800

I know OpenBSD vpn does not auth with LDAP directly. Is there a way to
achieve this?

We have an OpenBSD box acting as the firewall, but VPN connections are
forwarded to an internal Ms Proxy server using pptp. All the clients
are win2000 clients so they can use and benefit from ipsec.

I heard Active Directory uses kerberos authentication too, so is
kerberos supported in the vpn auth?

Theres another document that says openbsd can auth against LDAP using
RADIUS proxy. Does anyone know if that works with Windows2000 Active
Directory?

Pointers and experience stories will be much appreciated.



Relevant Pages

  • routing to a second router with PF
    ... VPN router (which encrypts the packets), ... Linksys VPN without hitting the OpenBSD GW. ...
    (comp.unix.bsd.openbsd.misc)
  • Re: VPN into PIX w/o cisco vpn client
    ... > RB> Hello I have recently been contracted to do some work for a client ... > RB> and I need access the clients site via VPN using a proprietary VPN ... then certainly you can make OpenBSD and the Cisco ... OpenBSD has IPSec in the kernel and IKE. ...
    (comp.security.ssh)
  • IPSEC / VPN question
    ... The VPN is set between an OpenBSD 4.0 GENERIC and a Checkpoint NG FP3. ... When I etablish the tunnel all is okay for a while. ... The problem appear to come from the OpenBSD side and that for 3.9 and 4.0. ... The Checkpoint side has 3DES/SHA/GRP2 with PRE-SHARED Secret for Phase 1 and 3DES/SHA for Phase2 enabled. ...
    (comp.unix.bsd.openbsd.misc)
  • Problem Properly Routing Between Interfaces (OpenBSD 3.7 + OpenVPN)
    ... I'm playing with setting up an OpenVPN connection on OpenBSD; ... VPN clients connected but I can't get any packets to route from the VPN ... OpenVPN connects clients on tun0, ...
    (comp.unix.bsd.openbsd.misc)
  • Re: Cant auth. on remote server using cable ISP dhcp settings
    ... > Maybe I'm missing something here, but are you using a VPN client or TSWeb, ... >> laptop cannot log on to any of the websites. ... so I configured my home dhcp to pass me the same as I get ... >> ping by fqdn and get a response, but it just dies on the auth part. ...
    (microsoft.public.windowsxp.work_remotely)