Tom's Hardware > Forum > General Networking > VPN, VoIP, Video Conferencing, Remote Connections > IP VPN - Cisco to Linux with NAT passthrough

IP VPN - Cisco to Linux with NAT passthrough

Forum General Networking : VPN, VoIP, Video Conferencing, Remote Connections - IP VPN - Cisco to Linux with NAT passthrough

Tom's Hardware: Over 1.4 million members in 6 different countries available to answer all your high-tech questions. Sign up now! Its free!
Word :    Username :           
 

Archived from groups: comp.dcom.vpn (More info?)

 

There is an initially bewildering array of VPN impementations (at
least to /this/ VPN novice) - can anyone help me get started with this
scenario by suggesting compatible techologies:

+----------------+
| Cisco PIX515e |
| as VPN gateway |
| at remote site |
+----------------+
|
|
Internet
|
|
+----------------+
| Linux firewall |
| NAT router |
+----------------+
|
Private LAN
|
+-------------------+
| Linux VPN gateway |
+-------------------+

While I don't have direct control over the Cisco device, it can be
configured to my specification, except that only DES is available (not
3DES - for some reason the ISP managing the PIX firewall does offer
the option of connection using stronger encryption technology without
the passing over of a large wad of cash. That's not too much of a
concern initially - I'd just like to see the tunnel up and running to
get started).

The linux router and firewall can have a dedicated public IP address
for the 'local' tunnel end point if required using DNAT and SNAT so
returned packets, rather than masquerading. That's about the level I
can define the set-up of the router - I don't have the option of
recomiling the kernel to include DES and IPsec.

The linux VPN gateway is a box I will have total control over, and
will also be a firewall to prevent the VPN connection being misused
(from either end).

All tunneled traffic is IP. From what I read here, and elsewhere, I
think I need something like L2TP, with IPsec and DES encrytion used at
transport layer for security. Initially planning on using shared key
for encryption to keep things simple.

Does that sound like I am thinking along the right lines, and if so,
do you have any pointers to docs on the web, especially when it comes
to the linux set-up?

Cheers
Richard

Sponsored Links
Register or log in to remove.
Tom's Hardware > Forum > General Networking > VPN, VoIP, Video Conferencing, Remote Connections > IP VPN - Cisco to Linux with NAT passthrough
Go to:

There are 1298 identified and unidentified users. To see the list of identified users, Click here.

Please mind

You are about to answer a thread that has been inactive for more than 6 months.
If you still wish to proceed, please ensure that your posting is original and does not duplicate or overlap any prior responses to this thread.

Add a reply Cancel
Sponsored links
  • Ask the community now
  • Publish
Ad
They won a badge
Join us in greeting them