- To: Phil Scarratt <fil@xxxxxxxxxxx>
- Subject: RE: [SLUG] Win2k - Linux VPN
- From: Greg Hosler <hosler@xxxxxxxxxxx>
- Date: Thu Mar 13 22:17:02 2003
- Cc: SLUG <slug@xxxxxxxxxxx>
- Reply-to: Greg Hosler <hosler@xxxxxxxxxxx>
CIPE is a heck of a lot easier to configure and get working, and there is a
windows client if you need to integrate a windows client into the vpn.
furthermore, it's more lightweight than IPSEC, and it is easier to configure
thru a firewall.
and one final note, it's included with the recent Red Hat distributions (RH7.3,
and RH8.0 -- Have not looked at RH7.2, but if you're running 7.2, you should
probably upgrade anyways...)
-Greg
On 13-Mar-2003 Phil Scarratt wrote:
> Hi all
>
> Sorry to interrupt all this talk about nominations....
>
> Anyone know a good howto or pointers on setting up a VPN from Win32
> clients to Linux server? I'm currently looking at setting up an
> IPSEC/L2TP tunnel but am having trouble getting IPSec to work. I tried
> to follow instructions at both
>
> http://www.strongsec.com/freeswan/install.htm
>
> and
>
> http://www.jacco2.dds.nl/networking/freeswan-l2tp.html
>
> to no avail as yet. I get packets arriving at the eth interface but not
> ipsec0 interface (tcpdump). No packets are being dropped or rejected but
> the logs say the following:
>
> Mar 13 16:25:39 neo pluto[28331]: "L2TP-CERT-WIN2KXP"[2] 192.168.1.201
>#3: unable to locate my private key for RSA Signature
> Mar 13 16:25:55 neo pluto[28331]: "L2TP-CERT-WIN2KXP"[2] 192.168.1.201
>#3: Peer ID is ID_DER_ASN1_DN: 'C=AU, ST=NSW, O=Draxsen, CN=rivendell'
>
> The error looks like an obvious oversight somewhere but I can't find it?
>
> Is there a better way? (apart from not using M$ OS at all that is).
>
> Thanks for any tips or info.
>
> Fil
> --
> Phil Scarratt
>
> --
> SLUG - Sydney Linux User's Group - http://slug.org.au/
> More Info: http://lists.slug.org.au/listinfo/slug
+---------------------------------------------------------------------+
You can release software that's good, software that's inexpensive, or
software that's available on time. You can usually release software
that has 2 of these 3 attributes -- but not all 3.
| Greg Hosler hosler@xxxxxxxxxxx |
+---------------------------------------------------------------------+