Koozali.org: home of the SME Server

Network over two sites (VPN)

Anonymous

Network over two sites (VPN)
« on: March 20, 2004, 01:03:05 PM »
I've been checking out the contribs and HOWTOs, but am still a little confused over what SME (6.0.1) can do out of the box.

I want to join two sites together using VPN over broadband, so they look like one big network. I also would like an SME server on one site to act as mail and file server for the combined sites.

The first option is to use a pair of Vigor routers to join it all together, and stick the SME on the network in server-only mode.

The second option - and this is where I am unsure - is to use a pair of SMEs, one at each end in server-and-gateway mode. The server at one end will be the mail server, and the other end just used to provide proxy, DNS routeing etc.

What do I need to do get get this working? Do any RPMs need installing, or is everything already on the standard box? Do I need to create my own templates to manually set up the routeing, or can it all be done through the server manager screens?

The HOWTOs describe various things that can be done, such as 'install OpenVPN' - but they do not explain why I would want to do that, or whether it is necessary and under what circumstances. There are also some HOWTOs that describe templates used to do some VPN stuff, but they are for earlier versions of SME.

Anyone got this working, without specialised VPN routers?

Thanks,

-- Jason

Offline stiperstones

  • *
  • 177
  • +0/-0
    • http://www.stiperstones.com
Stiperstones

http://wiki.contribs.org/Koozali_Foundation
Try the Wiki some great how's there

"My Licence".........

Don't report security issues here - Contact security at contribs dot org
Don't report problems here - Please report bugs @ http://bugs.contribs.org/
Don't ask the same question twice - Please search the forums, your question may have been asked before - Thank You.

Anonymous

Network over two sites (VPN)
« Reply #2 on: March 20, 2004, 11:56:30 PM »
Thanks, but I did find those links.

- HOWTO add IPSec (do I need to add IPsec?)
- HOWTO install OpenVPN (do I need to install OpenVPN? What does it do that SME does not already do?)
- HOWTO tunnel client PCs (I want to tunnel a whole network, not just client PCs)
- VPN Using PPTP (looks the most promising, but it a few things aren't clear: does this HOWTO fill some void that SME does not provide 'out of the box'? It is written for SME5.5 - does it still apply to 6.0? Does this method have any security implications - SSL is not mentioned at all?

I appreciate the link, but I think I probably need some further explanation, or advice from someone who has successfuly joined two sites into a single network, before embarking on this.

Thanks,

-- Jason

Anonymous

Network over two sites (VPN)
« Reply #3 on: March 21, 2004, 12:09:30 AM »
Okay - digging deeper, the "HOWTO install IPSec" looks like the contribution to create a VPN by tunnelling between two SME servers.

I think as a general note, the HOWTOs probably need a WHY section quite prominant, to explain what the HOWTO achieves in a higher-level. Some contribs do this very well, but those that don't could easily get overlooked, which is a bit of a shame considering the effort that the authors have put in to create these instructions.

That's just my initial observation, coming at this from the POV of someone trying to achieve some objective. Please don't read it as a whinge - I only hope it is treated as feedback to help improve this excellent knowledge base :-) (and one that is growing and improving by the day, I might add)

-- Jason

Anonymous

Site-to-site VPN
« Reply #4 on: March 21, 2004, 11:31:45 PM »
I think I'm going to buy a pair of Vigor routers. Seems a much easier way to link two sites than to hack around with this SME stuff. The time I've spent researching this issue, I could paid for the routers several times over by getting on with some other jobs...

-- Jason

italo

Network over two sites (VPN)
« Reply #5 on: March 22, 2004, 03:55:24 PM »
Have you looked at freeswan?

http://mirror.contribs.org/smeserver/contribs/dmay/mitel/contrib/freeswan/sme55/freeswan-howto.html

I found that howto that says works with 5.6, so theoretically should work with 6.0, but not necessarily. Then there is also some info in French, if you read it. Do a search for freeswan, I think it does exactly what your are looking for

Italo

Anonymous

Network over two sites (VPN)
« Reply #6 on: March 22, 2004, 07:57:05 PM »
Quote from: "italo"
Have you looked at freeswan?

http://mirror.contribs.org/smeserver/contribs/dmay/mitel/contrib/freeswan/sme55/freeswan-howto.html


I took a look at that. I think it needs some code compiled against the correct kernel, and that would need a bit of a development server to do properly (and a lot more knowledge). There is a site that offers pre-compiled RPMs for this, and it looks very good, but they have not created an RPM for 6.0 yet (they have refused to do so until 6.0 came out of beta, and that has only recently happened).

I guess timing is always the issue - I need this now, and several days of messing around with RPMs and discussion lists have not found me a solution, so a dedicated hardware approach is going to be the easiest/cheapest/most timely solution.

Just for completeness, I think this is the place to watch: http://lordsfam.net/downloads/production/freeswan/

-- Jason

italo

Network over two sites (VPN)
« Reply #7 on: March 22, 2004, 08:18:18 PM »
Hi Jason,

just to make sure...have you followed this thread
http://forums.contribs.org/index.php?topic=19393.msg80403#msg80403
and this
http://forums.contribs.org/index.php?topic=19393.msg80403#msg80403
Some were able to install it on 6

Italo

Anonymous

Network over two sites (VPN)
« Reply #8 on: March 22, 2004, 08:27:30 PM »
Quote from: "italo"
just to make sure...have you followed this thread
http://forums.contribs.org/index.php?topic=19393.msg80403#msg80403


Now that is a very interesting thread :-) I have no idea why I didn't come across it doing a search (perhaps search doesn't look at the title?)

I will give that one a few hours tonight, and try it out - thanks.

-- Jason

Anonymous

Network over two sites (VPN)
« Reply #9 on: March 22, 2004, 09:47:03 PM »
Did I mention timing? The freeswan.ca site appears to be down during the last few hours I have to try this thing out. Whether this is permanent or transient, I have no idea - but there you go, must be some kind of conspiracy to keep me away from VPNs ;-)

-- Jason

Offline Peter

  • **
  • 22
  • +0/-0
    • http://www.northwestlinux.co.uk
Peter
« Reply #10 on: March 23, 2004, 12:02:21 AM »
For your information the chap that was developing Freeswan has discontinued the project this could be why you are unable to go to his URL!

Peter

Anonymous

Re: Peter
« Reply #11 on: March 23, 2004, 01:00:06 AM »
Quote from: "Peter"
For your information the chap that was developing Freeswan has discontinued the project this could be why you are unable to go to his URL!

Peter


I think the official site (freeswan.org) is still working but the unofficial support site (freeswan.ca) - the one with the interesting RPMs on - just gives me DNS errors. It worked a few days ago, I'm sure.

-- Jason

Offline smeghead

  • *
  • 563
  • +0/-0
Network over two sites (VPN)
« Reply #12 on: March 23, 2004, 04:07:51 AM »
... http://www.freeswan.ca is up as of now
..................

Anonymous

Network over two sites (VPN)
« Reply #13 on: March 23, 2004, 10:31:33 AM »
Quote from: "smeghead"
... http://www.freeswan.ca is up as of now


Not from my ISP (in the UK), unfortunately. I think they must be having DNS problems somewhere - the DNS search takes ages, then gives up with "No DNS records".

-- Jason

italo

Network over two sites (VPN)
« Reply #14 on: March 23, 2004, 12:31:00 PM »
Jason,

I can get through...if you tell me exactly what you want I can get it for you and then send it your email address.

Italo
ilpuco_at_zerouno.info

Anonymous

Lost site: freeswan.ca
« Reply #15 on: March 23, 2004, 03:18:48 PM »
Quote from: "italo"
I can get through...if you tell me exactly what you want I can get it for you and then send it your email address.


Very kind of you. The two RPMs (I believe) are:

freeswan-1.99_x509_0.9.15_2.4.20_18.7-1
freeswan-module-1.99_x509_0.9.15_2.4.20_18.7-1

Both should be available here:

http://download.freeswan.ca/freeswan-x509/RedHat-RPMs/1.99/2.4.20-18.7/

My e-mail is: jason at academe co uk

Thanks :-)

italo

Network over two sites (VPN)
« Reply #16 on: March 23, 2004, 05:07:26 PM »
They are on their way!
Enjoy