Tuesday, January 25, 2005
Saturday, January 01, 2005
Work on VPN
Requirements:
- Linux GW behind NAT FW (LAN --- VPN GW --- ISP's NAT FW --- Internet --- RoadWarriors)
- RoadWarriors with Windows XP clients
- X 509 certificate
- Using Trustix Enterprise FW product
- FreeS/WAN FAQ (Trustix is based on FreeS/WAN)
- X 509 FreeS/WAN Install & Config doc (with doc on Virtual IP and wildcart subnets)
- Mentioning Windows XP Client & cert setup process
- Automated CMAK to streaming VPN client cert
- Trustix alone is not possible, having a problem with NAT packet
- Asking for suppot from Trustix and waiting...
- Problem detail is here (in Trustix forum)
- I think I found an idea from reading the docs above
- From this doc
- and from here
- This is a very cool NAT + VPN setting
- Advanced config: RoadWarrior with Virtual IP
- The plan to using Trustix package is now scrapped. Trustix comes with an old version of FreeS/WAN with X509, BUT without NAT-T patch. I couldn't patch the package myself without proper source made available by Trustix.
- Switched to using OpenVPN and it's done in a few days. I'll post more about this stuff later on.