Koozali.org: home of the SME Server

IPSec VPN connect from W2K client to SME 5.6u6

Joerg Panthoefer

IPSec VPN connect from W2K client to SME 5.6u6
« on: December 10, 2003, 04:54:29 PM »
Hallo,

I'd like to connect from a notebook with windows 2000 prof. or windows xp to the sme server 5.6u6.

The VPN connection should be IPSec (FreeSwan).

Both sides have dynamic IP-Adresses. The SME Server has a host-adress at dyndns.org.

>>>>> SME-Server <<<<<

On the SME Server I've installed the following freeswan packages:

-> devinfo-freeswan-1.99-8sme56.noarch.rpm
-> e-smith-packetfilter-1.13.0-04.noarch.rpm
-> freeswan-1.99_2.4.18_5-0.i386.rpm
-> freeswan-module-1.99_2.4.18_5-1es1.i586.rpm

With the test "ipsec verify" I get the following result:

Checking your system to see if IPsec got installed and started correctly
Version check and ipsec on-path                             [OK]
Checking for KLIPS support in kernel                        [OK]
Checking for RSA private key (/etc/ipsec.secrets)           [OK]
Checking that pluto is running                              [OK]
DNS checks.
Looking for forward key for FLDTESTLABOR                    [OK]
Does the machine have at least one non-private address      [OK]

In the Server-Manager is an item "IPSEC VPN" under "Security". There I can see the public encryption key and send it by email to the admin.

>>>>> Windows 2000 Prof. Client <<<<<

At the windows client I've installed:

ServicePack 2
The content of package.zip to C:\Programme\IPSec (from http://vpn.ebootis.de)
ipsecpol_setup.exe to C:\Proframme\IPSec (from the MS homepage)

When I start the MMC "ipsec.msc" I could import a certificate.

>>>>> Problem <<<<<

Where can I place the key generated from the SME Server and send by email
or
how to generate a key file for import into windows 2000?

ryan

Re: IPSec VPN connect from W2K client to SME 5.6u6
« Reply #1 on: December 13, 2003, 02:35:04 AM »
Joerg,

I hope your able to get it working.  I have looked into this also and found it too involved.  There is a simple solution, use IPCop as your VPN router.  You can use Linksys VPN firewall/routers as endpoints or other IPCop servers.  A linksys VPN router costs $130.  I have 5 sites all fully routed using IPCop and Linksys VPN firewall/routers.  I also use SME, but only with its default functions.......IPCop is very easy to set up as a firewall.  IPSEC VPN is a snap compared to freeswan on SME.  IPCop also has a true DMZ subnet as a stock option.   I let IPCop handle my network & routing issues, SME handles network services.

ryan