Good Afternoon,
I'm still in hell I guess. I've tried about everything I can think of. Here's my network layout simply:
Note: All these boxes have separate inside addresses as well as separate external addresses.
Site 1 - Main Site
171.17.1.1 << Mail/web server with external ip address matching the domain name. SME 5.6 plain with nothing installed but portforwarding and oneorzero helpdesk. That's it nothing more.
172.17.1.5 << Proxy server and default gateway to local network. Port forwarding installed, content filtering, and netprobe. I have put in a route add statement that redirects all traffic to the other site's network (172.18.*) to go to 172.17.1.6. I installed Shad Lord's freeswan contrib as well as followed his how-to with no success. Ifconfig doesn't even show an ipsec0 but in the server-manger, it shows the IPSEC VPN panel and gives me a secret.
172.17.1.6 << IPCOP v1.3.0 -- stock install, changed squid.conf to make the port for the proxy be 3128 instead of 800. Created a VPN and used a key that I had saved from a previously working SME 5.1.2 VPN as the secret. Exported the vpn information so I could import it on the other side.
When I do a tracert from the Win2k server on the inside of the network to the remote side's server, it will hop through the ipcop box then to the local cisco router and then finally to the remote cisco router. It dies here.
I get on the IPCOP box and ping the internal address of the remote IPCOP and it doesn't do anything.
Site 2 - Remote Site
172.18.1.1 << SME 5.6 stock install with only port forwarding installed. A route add directs all traffic bound for 172.17.* to route through 172.18.1.3.
172.18.1.3 << IPCOP 1.3.0 stock install and nothing changed. Imported the vpnconfig.dat file from the main site's IPCOP box. Both sides opened up and showed to be running. I got on the IPCOP box and was not able to ping the internal IP address of the main site's IPCOP box. I got on the Win2k server at the remote site and was able to ping the internal address of the main site's IPCOP box. I was also able to putty to the main site's IPCOP box using the internal IP address of the main site's IPCOP box.
Both sides show some traffic. The only thing I really need to do right now is to allow the MS Outlook clients to attach to the mail server on the main site using the internal IP address (172.17.1.1).
Would I be better served going back to 5.1.2? I've heard and read both sides of this argument. On one side folks say that everything with Shad Lord's contrib on 5.6 works and others say it doesn't and they are going back to <5.5 as fast as they can. I'm cornfused!!!
On another note that I've briefly touched on earlier in this thread was that the two Cisco 1601 routers that I have at both locations will route 172.16.* traffic from one site to the other site through an IPSEC tunnel. I have been trying to figure out how I would setup a box that could utilize this tunnel without jeapordizing(?) the local networks at both sides.
A penny for your thoughts, and yes, this is truly Walter Padgett not some anonymous person,
Walter "Wally" Padgett