Koozali.org: home of the SME Server

VPN from Windows through SME 5.5 gateway

John Farmer

VPN from Windows through SME 5.5 gateway
« on: September 29, 2002, 09:46:44 AM »
Hi all,

This question is NOT about accessing SME using VPN.  I'm running a SME 5.5 server as my internet gatway in my home-office, to service my Windows NT/2000 workstations.  On one NT4.0 (sp6) workstation, I'm running VPN-1 Secure Client from CheckPoint software, used to access systems outside of my home network (VPN systems are for the day job).

When I ran this nt workstation directly to my cable modem connection, VPN worked fine.  Since I installed SME as the internet gateway, and run the NT workstation through it, my CheckPoint VPN doesn't work.  It always times out giving an error "Error: Communication with site company-name has failed".

How do I configure SME to allow VPN outside the network?  Anything special to consider here?

Thanks,

John Farmer

AJ

Re: VPN from Windows through SME 5.5 gateway
« Reply #1 on: September 29, 2002, 05:48:13 PM »
I have the same problem in that I am trying to VPN into work using Cisco VPN client software and need a way to allow the VPN traffic through e-Smith.

Andrei

Re: VPN from Windows through SME 5.5 gateway
« Reply #2 on: September 29, 2002, 05:52:13 PM »
It sounds like you may have to install the port forwarding rpm and forward whatever ports checkpoint has designated for the Secremote client to the workstation. You have to find out what ports the Secremote client uses when connecting to checkpoint.

Terry Brummell

Re: VPN from Windows through SME 5.5 gateway
« Reply #3 on: September 29, 2002, 06:00:42 PM »
Check Point VPN-1 Secure Client works fine for me.  My workstation is 2000 Pro SP3 and the SME is 5.1.2.  No additional software was needed on the SME side of things.  Hope this helps for you.

Terry

Thomas S

Re: VPN from Windows through SME 5.5 gateway
« Reply #4 on: October 02, 2002, 02:36:35 AM »
Try activating ipsec in 5.5

/sbin/e-smith/config setprop masq ipsec yes
/sbin/e-smith/signal-event remoteaccess-update