Koozali.org: home of the SME Server

firewall-to-firewall tunnel

John

firewall-to-firewall tunnel
« on: May 25, 2001, 11:09:52 PM »
I am needing to set up a VPN, and the client has concerns about meeting the new requirements for IP-Sec / PPTP.   Because he is running NT 4 workstations, he would prefer to have a firewall-to-firewall tunnel.  If I understand correctly, this is how e-smith handles VPN.
Is this correct?
Thanks-
John

Justin

Re: firewall-to-firewall tunnel
« Reply #1 on: May 25, 2001, 11:13:19 PM »
John wrote:
>
> I am needing to set up a VPN, and the client has concerns
> about meeting the new requirements for IP-Sec / PPTP.

These are mutually exclusive protocols.
 
> Because he is running NT 4 workstations, he would prefer to
> have a firewall-to-firewall tunnel.  If I understand
> correctly, this is how e-smith handles VPN.

Not natively. There have been some developer contributions using FreeSwan (IPSEC) for site to site projects. Currently e-smith comes "out of the box" with client to server VPN using the (PPTP) protocol.

Justin.

John

Re: firewall-to-firewall tunnel
« Reply #2 on: May 25, 2001, 11:58:18 PM »
Does e-smith support a 3-DES IP-Sec tunnel?

Justin

Re: firewall-to-firewall tunnel
« Reply #3 on: May 26, 2001, 12:01:25 AM »
John wrote:
>
> Does e-smith support a 3-DES IP-Sec tunnel?

Not yet, it is something I have wanted to do for a while but it looks like Jeb has something working so I have been waiting on him.

Personally I hope they skip 3DES and go straight to AES. The package will most likely support any symmetrical encryption protocol you want to use.

Justin

John

Re: firewall-to-firewall tunnel
« Reply #4 on: May 26, 2001, 12:45:27 AM »
is there and e.t.a. on the release of that package?

Justin

Re: firewall-to-firewall tunnel
« Reply #5 on: May 26, 2001, 12:47:44 AM »
John wrote:
>
> is there and e.t.a. on the release of that package?

None that I am aware of. They are quite busy with some other features and I don't know where this would fall on the priority list.

If your looking for something immediately I would take a look at Jeb Campbell's contributed FreeSwan rpm. (keep in mind it is unsupported)

Justin