Koozali.org: home of the SME Server

Sean Gray PPtP Multipoint routing problem

Luis

Sean Gray PPtP Multipoint routing problem
« on: June 19, 2003, 09:35:43 AM »
Hi!.. i have 2 SME with adsl connection both.

I need routing betwen lan's..

I use 192.168.2.0 net address for "SME server" and 192.168.1.0 net address for "SME Client".

I Configure pptp client, connect to server and have full access to .2.0 lan  on server (server and other host on this lan)

In the server side, i can ping to "SME client server" and have reply from server but  don't have reply from other host in the "client lan".

A "tcpdump -i ppp2" (tunnel) in the "SME client server" display packet from the "SME server machine" but echo reply is generate only for ping to "SME client IP address" and not for  other host in the client LAN.

Is this a Firewall configuration problem?..

The SME version are both SME 5.5U6

I am lost... thanks!!... and sorry by the english.

Kelvin

Re: Sean Gray PPtP Multipoint routing problem
« Reply #1 on: June 19, 2003, 04:12:07 PM »
Hi Luis,

You're using the wrong tool for the job. You should be using the IPSec VPN contrib (check it out at contribs.org) and not PPTP.

Kelvin

Luis

Re: Sean Gray PPtP Multipoint routing problem
« Reply #2 on: June 19, 2003, 05:18:18 PM »
Thank.. but i don't have Fixed IP address and IPSEC required this. 8)..

I Have sucefully implement IPSec with other SME 5.5 Server but i used ip fixed in both servers.

I recheck all step in PPtP Multipoint and review IPSEC HowTo

Thanks a lot.

Luis

Kelvin

Re: Sean Gray PPtP Multipoint routing problem
« Reply #3 on: June 19, 2003, 05:21:16 PM »
Luis,

I believe the current IPSec contrib was supposed to address the problem with not having a static IP address. Check the contrib info again.

Kelvin

Luis

Re: Sean Gray PPtP Multipoint routing problem
« Reply #4 on: June 19, 2003, 05:51:54 PM »
8(... i have not find any reference in the IPSEC VPN howto for a implementation with dynamic IP.

I am lost...
Thank's a lot..

Luis

Kelvin

Re: Sean Gray PPtP Multipoint routing problem
« Reply #5 on: June 19, 2003, 06:28:43 PM »
Luis,

I'm not sure which how-to you are looking at. The how-to I'm referring to is hosted by Shad Lords.

If you look at the example setup given in the How-to, you will notice that the external IP of the sites are given as either an IP address or as a domain name. Now, assuming you are able to maintain your dynamic IP updated to your domain name (or one of the many dynamic domain names provided by dyndns and others), you should be able to use the IPSec contrib with dynamic IPs.

Kelvin

Luis

Re: Sean Gray PPtP Multipoint routing problem
« Reply #6 on: June 19, 2003, 06:56:15 PM »
THANKS Again.. i find the howto in

http://lordsfam.net/downloads/production/freeswan/freeswan-howto.html

But this is only for  SME 5.6.

The big Diference in the configuration is that it not requiered external IP Gateway and the version for 5.5 requierd this.

THANKS Again..!!


Luis

ryan

Re: Sean Gray PPtP Multipoint routing problem
« Reply #7 on: June 20, 2003, 09:56:25 AM »
Take a look at IPCop.  It installs on older systems and is a IPSec VPN router that allows for dynamic addresses.  I have put IPCop at each of my sites and have SME behind it either on the lan as a server only, or as a server gateway, with the external SME nic residing on the DMZ lan from IPCop.  IPCop also has built in Port Forwarding and Snort, plus it's web interface is easy and powerful.  The IPCop download is under 30mb...but is is only a router..no users, no email, no file or print server, so it is not a replacement for SME.  

My life is simpler know that I use SME for stock services.......trying to keep SME up to date while keeping the addon services working was a big headache for me.  

good luck,

ryan