Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Using VPN tunnels for specific ports

Posted on 2013-05-24
14
Medium Priority
?
864 Views
Last Modified: 2013-06-22
Is it possible to use VPN tunnel for one specific port and let all the other traffic follow the normal unsecured ISP path? Can this be done by software application. On a server I have openVPN installed and squeezeserver ( with music database).
Now I would like to connect my squeezebox, wich is located at another office, to this server.
So I'd like to be able to specify that only the squuezebox   connects to the remote server through the VPN tunnel...
0
Comment
Question by:mycofilip
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 7
  • 4
  • 2
  • +1
14 Comments
 
LVL 11

Expert Comment

by:John Easton
ID: 39194830
I don't know if you can filter VPN traffic by port, however you can route by IP Address and network - this is standard is many business VPN setups and I think would achieve what you are looking for.

For example, your home network could have the IP range 192.168.1.x, the network your squeezebox is on has IP range 192.168.2.x and the VPN tunnel (and network routing) is configured only to route traffic to the 192.168.2.x network through the VPN while local traffic and internet traffic is uneffected.

This is how we connect small remote offices back to our Head Office!

Hope this helps.
0
 
LVL 71

Expert Comment

by:Qlemo
ID: 39195177
"Port routing" would require a very sophisticated router / VPN device. It is called "policy-based routing", and allows for more complex rules than target IPs. But I agree in your case the target IP routing should suffice. Each router and OS is able to do that. But how to do it depends on your actual setup. Most simple is if the OpenVPN client/server is also the Internet gateway for each site, then all you need is to set up the routes to the other site in both OpenVPN configs.
0
 

Author Comment

by:mycofilip
ID: 39196766
I have a modem/router from my ISP wich gives 192.168.0. x ip adres to the clients.
The server is also behind a ISp router with IP 192.168.1.2 ( but I can use dyndsn here).
So on the server site I install open VPN? But what about the client site?  This is where the squuezebox is located. But instead of installing the squeezeserver software on  a pc at that location I would want to install the VPN client wich connects the squuezebox to the open vpn server ...
0
Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

 

Author Comment

by:mycofilip
ID: 39196808
Seems like openvpn access server doesn't run on windows homeserver directly. Is it really necessairy to install a virtual Linux system to run this ?
0
 
LVL 71

Expert Comment

by:Qlemo
ID: 39196969
You don't need OpenVPN Access Server. The free OpenVPN Community server works, and it runs on ANY Windows OS. WHS should not be an exception.
0
 
LVL 3

Expert Comment

by:corower
ID: 39200464
the simple answer is "no, you can not use VPN tunnel for one specific port". TCP/IP can distinguish paths only by IP, as routing decision is made on OSI level 3 - = based on IP address.  Tunneling (VPN) is also working on L3. TCP port is extra information, that is not used in routing decision.

however. you may apply some tinkering to work that around. i.e. - you open a VPN towards your sqeezeserver, and route all trafic to this machine (and only to this machine) through that VPN. just make sure, you do not install default route from that VPN :) as long as yo do not use other services than sqeezeserver, that traffic will be routed through VPN.

the you should configure windows server as a RAS (VPN dial-in) server and a client on your side. here is a manual, that looks pretty good -- http://thedigitalmediazone.com/2012/03/26/how-to-set-up-vpn-for-windows-home-server-2011/

when you configure VPN connection (client side), get into ICP advanced settings and uncheck "use default gateway on this connection". then all traffic except that subnet on VPN will continue to go directly through old connection.
0
 

Author Comment

by:mycofilip
ID: 39212745
OThanx for yur answer corower. The VPN is setup on de homeserver. But can I change the VPNport, sice my is^p blocks everything below port 1024 ?
When you say to open a VPN towards the squeezeserver you mean to open a VPN from a pc on the client site , where the squeezebox is installed? I can't make a vpn connection  from a squeezebox can I?
0
 

Author Comment

by:mycofilip
ID: 39212810
Sorry but can't seem to find " get into ICP advanced settings "
0
 
LVL 71

Expert Comment

by:Qlemo
ID: 39212816
That's a typo. ICP => TCP
0
 

Author Comment

by:mycofilip
ID: 39212819
???
0
 

Author Comment

by:mycofilip
ID: 39212821
Ok, understand typo = mistype ;-)
0
 

Author Comment

by:mycofilip
ID: 39214336
This is how far I got till now.
On the client site I have a pc that has IP 192.168.0.22 from local ISP router.
Also connected to that router is the squeezebox wich I gave fixed IP 192.168.1.20.

At the server site I have the same ISP router that gives the server IP 192.168.0.50.
On this server I have VPN server enabled that gives IP 192.168.1.90 to VPN client.
On this server I have squeezecenter installed.

Now, at the clients site I could make a VPN connection to the server and got the 192.168.1.90 IP , but when I can't connect the squeezebox to the squeezecenter software on the server site.
How can I let the squeezebox tunnel through the VPN i set up ?
0
 
LVL 71

Accepted Solution

by:
Qlemo earned 1500 total points
ID: 39214888
Confusing setup. Each independent site needs to have one and only one but distinct network. Else you get into a lot of unnecessary trouble with proper routing.
That is, your client site should have 192.168.0.x, your server site 192.168.1.x, and the OpenVPN network 192.168.2.x.

The OpenVPN server config then needs a
    push route 192.168.1.0 255.255.255.0
to push the necessary route for the server site to the  client.
0
 
LVL 3

Expert Comment

by:corower
ID: 39214890
Hi!

it seems, we're getting a bit to heavy on heads on sundays evening. maybe a small picture would help us (okay, at least - me) to understand what is the situation?
0

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This paper addresses the security of Sennheiser DECT Contact Center and Office (CC&O) headsets. It describes the DECT security chain comprised of “Pairing”, “Per Call Authentication” and “Encryption”, which are all part of the standard DECT protocol.
I originally wrote this article to compare SARDU and YUMI, but have now added Easy2Boot, since that is the one I currently use and find the easiest to create and alter.
If you're a developer or IT admin, you’re probably tasked with managing multiple websites, servers, applications, and levels of security on a daily basis. While this can be extremely time consuming, it can also be frustrating when systems aren't wor…
We’ve all felt that sense of false security before—locking down external access to a database or component and feeling like we’ve done all we need to do to secure company data. But that feeling is fleeting. Attacks these days can happen in many w…
Suggested Courses

636 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question