|
Re: Testing OpenVPN?: msg#00303security.firewalls.m0n0wall
-------- Original Message -------- I have an idea as to what causes this, and I believe it would be avoided This is the reason why I've asked Manuel to add a lightweight cron daemon to m0n0wall. This would make possible to have the ping command issued on a periodic basis, not only at boot time. And it may have other uses. The requirements are: I've already tried this. On the local network, I've set up a cron job on a server that periodicly ping the LAN IP of the remote m0n0wall box. But on the remote network, there is no machine no machine running 24/24 and there are only Windows machines and no sysadmin at all :-( The trick only work if both sides of the tunnel can send ping packets. This is why it should be included in m0n0wall. Justin is about to release a ping patch, so we'll have to wait... The basic idea is to insure that the tunnel is brought up from the I don't see what this option actually does... The other issue is how the kernel prioritizes conflicting send SAs. There's no simple answer to this, since preferring older SAs can cause I really agree for the newest SA choice. I can wait for one minute for the new SA to be negotiated, but can't wait for hours for the old SA to be purged. The choice between the other two is based on the net.key.preferred_oldsa Very interesting! I've just noticed this parameter in our old Netopia (Cayman) R3100 ISDN router (not tested - just looked at the menu entries): You can try to use old SA first or force new SA use. Yes, it can be the clue to our problem... Combined with a good keepalive feature, the IPsec tunnels can be always available, even within a few minutes after a reboot. Be sure that the IP addresses used for the PPTP link are not in the tunnel I know the IP range rules, but just in case, this is what I had: Site A m0n0wall 192.168.1.254 Windows 2000 192.168.1.5 (PPTP client) Site B m0n0wall 192.168.5.254 (PPTP server - no PPTP forwarding) PPTP config: server address 192.168.50.254 remote address range 192.168.50.1/28 Works well, but when active, make IPsec tunnel not respond... Even if you get IPsec fully working, I recommend having the PPTP option I'll do that, sure ;-) Thanks you for investigating, Fred. -- Vincent |
|
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| Previous by Date: | Intel Pro/1000 MT Dual Port Server Adapter + MonoWall: 00303, Mark Wass |
|---|---|
| Next by Date: | RE: Is a NAT on PPTP interface a taboo subject ?: 00303, Fournaux Nicolas |
| Previous by Thread: | Re: Testing OpenVPN?i: 00303, Fred Wright |
| Next by Thread: | Re: [m0n0wall-dev] Getting started with development: 00303, Patrik |
| Indexes: | [Date] [Thread] [Top] [All Lists] |
| News | FAQ | advertise |