Solved

Ipcop OpenVPN & LDAP

Posted on 2010-08-15
10
1,436 Views
Last Modified: 2012-05-10
How can I setup VPN using Ipcop with OpenVPN and have LDAP authentication, is this possible?

I believe it is possible using Endian, but was curious if it was possible using Ipcop and OpenVPN.

Thanks.
0
Comment
Question by:rnits
  • 5
  • 5
10 Comments
 
LVL 10

Expert Comment

by:pfrancois
ID: 33444991
Yes, it is possible: you have to install two addons on ipcop:

advproxy; see: http://www.advproxy.net/
openvpn (also called zerina): see http://www.zerina.de/

About IPCop addons, see webpage: http://www.ipcop.org/index-pn.php?module=pnWikka&func=history&tag=IPCopAddons

0
 

Author Comment

by:rnits
ID: 33445136
But, can I use Ldap Authentication when using OpenVPN, so the user is using their username/password that is on Ldap.

Thanks.
0
 
LVL 10

Expert Comment

by:pfrancois
ID: 33445201
What kind of identification do you want to do: identifying a user on the LAN to allow him access on the Internet?
0
Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

 

Author Comment

by:rnits
ID: 33445227
Well, OpenVPN needs a user/password to get into the network.  I want to authenticate this to the ldap server.  

Basically, authenticate users that log in using OpenVPN to the ldap server.
0
 
LVL 10

Expert Comment

by:pfrancois
ID: 33445548
I understand in your case that the LDAP server is on the local LAN and that users wants to connect to a remote VPN. So you use your local OpenVPN as a client for connecting to remote VPNs, not as a server for incoming connections from outside. Am I right? I suppose the IPCop is locally running.
0
 

Author Comment

by:rnits
ID: 33446259
So here is the diagram:

External Network (Red Network) --> IP Cop Firewall/OpenVPN Server --> Internal Network (Green Network) --> Ldap Server (Windows 2k3 Server)

So the OpenVPN Client would connect to OpenVPN Server to get access to the Internal Network.

0
 
LVL 10

Expert Comment

by:pfrancois
ID: 33446621
Oh, I understand: you try to connect to the green network from outside. In that case, you don't need the ldap server of advproxy. OpenVPN is enough.

But... as long as the tunnel is not open, you don't have access to the the ldap server. OpenVPN has his own system of authentication with certificates. As far as I know, you would have to authenticate twice: once for opening the VPN tunnel, normally with certificates (my VPN client connects transparently), and second with ldap once you are on the green network through VPN.

I fear the authentication of ldap and vpn are not compatible.
0
 

Author Comment

by:rnits
ID: 33446868
Hence, I do not want to authenticate twice.  That is my main problem. :)

I was hoping there was another way of setting up OpenVPN to authenticate only once.
0
 
LVL 10

Expert Comment

by:pfrancois
ID: 33447436
OpenVPN implies a very secure  way of authentication, with encrypting and certificates. ldap is just checking a pair of username/password but offers no encrypted communication. ldap is not strong enough for supporting the level of ssh tunneling implied by OpenVPN.

I propose two solutions:

a) use clients that authenticate in a user transparent way, at least the VPN part;

b) connect through ldap without tunneling but simply by opening the corresponding port on IPCop (do NOT do that, it is very unsecure).
0
 

Accepted Solution

by:
rnits earned 0 total points
ID: 33454213
So, here is what I found:

IPCop with OpenVPN can not authenticate with an LDAP server.

0

Featured Post

Master Your Team's Linux and Cloud Stack

Come see why top tech companies like Mailchimp and Media Temple use Linux Academy to build their employee training programs.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
IT Contract Fee 17 148
Random Terminal Server disconnections. 2 176
what kind of tasks do I need to conduct in order to configure ip-sec in AWS 1 38
eigrp in site-to-site vpn 4 38
Overview Often, we set up VPN appliances where the connected clients are on a separate subnet and the company will have alternate internet connections and do not use this particular device as the gateway for certain servers or clients. In this case…
If you use NetMotion Mobility on your PC and plan to upgrade to Windows 10, it may not work unless you take these steps.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

778 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question