[2 days left] What’s wrong with your cloud strategy? Learn why multicloud solutions matter with Nimble Storage.Register Now


VPN between two firewalls

Posted on 2000-03-12
Medium Priority
Last Modified: 2010-03-18
I have two 2.2 Linux machines acting as ipmasq firewalls in two different locations.  Both have permanent internet connections.  I would simply like the firewalls to securely route traffic between each other.  
What are my options?  Can you point me to a good source of information, other than the Linux HOWTOs?
Question by:hansendc
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
LVL 40

Accepted Solution

jlevie earned 300 total points
ID: 2610260
In addition to the methods described in the various VPN HowTo's there's FreeS/WAN (http://www.xs4all.nl/~freeswan/).

Author Comment

ID: 2610616
Although that looks like a very viable solution, I would prefer something that doesn't require kernel patching.  I get nervous adding extra stuff into the kernel.  
Is the IP tunneling stuff in the kernel for VPNs?
LVL 40

Expert Comment

ID: 2610813
Seems to me that the basic facility is there, but it's not usually enabled by default. So in a way that's kind of a kernel patch also.

I can understand your reluctance to fiddle with the kernel. But if the patch is in reasonably widespread use without any reported problems it's probably a low risk. Something that looks quite attractive to me, and that I've been playing around with is the Linux Router Project (LRP). The blurb on it is at http://www.linuxrouter.org/.  Basically you take a 486 or better with a floppy drive and make it into a dedicated router that can do a number of additional things (firewall, IPMasq, caching or nornal DNS, etc).

I'm in the process of trying to build one onto a 200Mhz pentium board using an LS-120 for the boot medium as I've outgrown a floppy. I think a 2.88 super floppy would be okay, but I have the LS-120's and don't have any super floppies. My goal is to have a zero maintenance 7/24 box that can be remotely administered and will do:

IPMasq/firewall to the Internet
DNS for my internal net & forwarder
DHCP server for local net
FreeS/WAN IPSEC to my Cisco 7200 at work.

I could do a Linux VPN with a pair of the boxes, but I'd rather get FreeS/WAN onto it so that I only have to do one side.

It might be worth looking into.

Expert Comment

ID: 2617591
Excuse the ignorance - what's an LS-120 ?
LVL 40

Expert Comment

ID: 2617837
LS-120, aka Floptical drive, aka Super-disk. It's a drive that can read/write standard 1.44Mb floppies and with LS-120 media read/write 120Mb diskettes. Go to http://www.imation.com/products/data/content/0,1011,1031,00.html for a complete description.

I love 'em... As I've replaced my older MB's with those that support the LS-120's in the bios as a boot media I've also replaced the floppies with LS-120's. It gives me a very convenient way to move modest sized data chunks around (and doesn't do a bad job at small backups). And they're fast, really, really fast compared to a floppy.

Featured Post

Enroll in October's Free Course of the Month

Do you work with and analyze data? Enroll in October's Course of the Month for 7+ hours of SQL training, allowing you to quickly and efficiently store or retrieve data. It's free for Premium Members, Team Accounts, and Qualified Experts!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I have seen several blogs and forum entries elsewhere state that because NTFS volumes do not support linux ownership or permissions, they cannot be used for anonymous ftp upload through the vsftpd program.   IT can be done and here's how to get i…
Note: for this to work properly you need to use a Cross-Over network cable. 1. Connect both servers S1 and S2 on the second network slots respectively. Note that you can use the 1st slots but usually these would be occupied by the Service Provide…
If you're a developer or IT admin, you’re probably tasked with managing multiple websites, servers, applications, and levels of security on a daily basis. While this can be extremely time consuming, it can also be frustrating when systems aren't wor…
This tutorial will teach you the special effect of super speed similar to the fictional character Wally West aka "The Flash" After Shake : http://www.videocopilot.net/presets/after_shake/ All lightning effects with instructions : http://www.mediaf…
Suggested Courses

656 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question