Koozali.org: home of the SME Server

Site-to-site VPN between 2 SME servers

lisajeanrieken

Site-to-site VPN between 2 SME servers
« on: February 08, 2007, 01:07:21 PM »
Has anybody set up a site-to-site VPN between two SME 7.0 servers???
Desperately need this configuration and any other relevant information! Thanks so much!  :)

Offline crazybob

  • *****
  • 894
  • +0/-0
    • Stalzer R&D
Site-to-site VPN between 2 SME servers
« Reply #1 on: February 08, 2007, 02:49:03 PM »
If you think you know whats going on, you obviously have no idea whats going on!

Offline Jean-Philippe Pialasse

  • *
  • 2,907
  • +11/-0
  • aka Unnilennium
    • http://smeserver.pialasse.com
Site-to-site VPN between 2 SME servers
« Reply #2 on: February 08, 2007, 04:01:44 PM »
this first is for a routed tunnel


here are another for a bridged tunnel (a rpm contrib):

http://sme.firewall-services.com/spip.php?article4

I am currently working on a bridged one with still some limitations:

-able to work one each sme in the "local network" on win$ computer using host name
-able to access services hosted by lan computers like http,vnc on each lan from the other lan
-able to see connected computer
- NOT able to access the shared folder on a computer on the other LAN (but as i only want to works with ibays it is ok for me)

Offline compdoc

  • *
  • 226
  • +0/-0
Site-to-site VPN between 2 SME servers
« Reply #3 on: February 13, 2007, 11:09:28 PM »
A customer needed a VPN between Denver and Las Vegas. and Openvpn seemed the best way.

I tried using SME to do a site to site, but its a lot of work since Openvpn isnt included in the Server distro.  

A routed tunnel seemed best after testing, and ideally, you want the routes automatically pushed to the users.

If you want two way communication, you need two tunnels with each server being both a client and server.

I'd recommend Endian Firewall if you want it working quickly, or for inspiration - I'd love to see something like this added to SME...

Offline Jean-Philippe Pialasse

  • *
  • 2,907
  • +11/-0
  • aka Unnilennium
    • http://smeserver.pialasse.com
Site-to-site VPN between 2 SME servers
« Reply #4 on: February 14, 2007, 11:31:27 PM »
a simple tunnel is supposed to be two way communication.