Setup a VPN across ADSL

Network problem solving and tweaks
Post Reply
douglash
Registered User
Posts: 934
Joined: 07 Jun 2007, 02:00
Location: Durban

Setup a VPN across ADSL

Post by douglash »

Hey all you in the know... :wink:

Quick question(s):

1. How do you setup a VPN across the internet(ADSL)?
2. What all would i need to do this?

Shotto!!
Lost49
Registered User
Posts: 14
Joined: 14 Aug 2008, 02:00

Post by Lost49 »

First of all is this a Router/Firewall to Router/Firewall VPN or just a pc to a server VPN?

For the first most routers nowadays come with some sort of setting to set this up. Just plug in ip addresses/hostnames and a password or cert and youre a for an apple. No need to forward ports or anything. You will need different subnets on each end otherwise routing gets confused.

If you want to connect to a VPN server using the windows VPN connection you'll need a server with the correct ports forwarded to it from the router. For PPTP it will be 1723. Again you need seperate subnets so things don't get confused...

So for option one you need two vpn end points which will be connected pretty much all the time and for option two you need a server and a pc or whatever.

There are a couple of proprietry apps as well that Cisco uses where you need a client for it. An open source app such as OpenVPN is also available.
douglash
Registered User
Posts: 934
Joined: 07 Jun 2007, 02:00
Location: Durban

Post by douglash »

Well, then it is just from an ADSL connection at one location to another ADSL connection at a different location...

just a straight connection between the two (so they are networked)..

so from a router through a vpn (end point?) to another vpn to a router?

is that right?

where can i get these vpn end points from?

lol - i'm such a noob at this!!
Lost49
Registered User
Posts: 14
Joined: 14 Aug 2008, 02:00

Post by Lost49 »

What kind of ADSL routers are you using?
Anything not Telkom should have this built in and pretty easy to set up.

Also you'll need some kind of dynamic dns updater for when the IP gets reset.
UrBaN
Registered User
Posts: 12811
Joined: 02 Feb 2005, 02:00
Location: JHB East
Contact:

Post by UrBaN »

Yup, you'll need either static IPs or or dynDNS to set this up, otherwise the router won't know what to connect to (ie which IP address).
Image
to ápeiro anima
Charger14
Registered User
Posts: 302
Joined: 05 Jul 2004, 02:00
Location: In my chair

Post by Charger14 »

Your endpoint is whatever your dialing into, be it a server 2003 RRAS server, another router or a 'nix box.

The Telkom routers can do the port forwarding and support VPN passthrough.

But yeah what routers you got on each side?
Is this thing on?Helloooo?
douglash
Registered User
Posts: 934
Joined: 07 Jun 2007, 02:00
Location: Durban

Post by douglash »

the one is a Billion 802.11G ADSL 2 + router Model no. BIPAC7401VGP:

confirming the other one still, but probably the same, if not, it's the mega1000WR i think...

can you do this via the routers themselves then?
Lost49
Registered User
Posts: 14
Joined: 14 Aug 2008, 02:00

Post by Lost49 »

Yup you should be able to do it on two Billions.

Head to www.dyndns.com to setup a dynamic host name account.
This will allow you to know what IP you have.

Otherwise look for OpenVPN on Google. That's a pretty secure VPN option and they provide good how-tos for both Linux and Windoze.
RobThePyro
Registered User
Posts: 1210
Joined: 04 Dec 2006, 02:00
Location: Durbz!
Contact:

Post by RobThePyro »

IMO the easyist(and quickest, most uncomplicated) way to network two pc's over the net is Hamachi

http://en.wikipedia.org/wiki/Hamachi
https://secure.logmein.com/products/hamachi/list.asp
All the info is there ^^^
Image
PCF Dumbass of the Month Award!
"My lungs are in SLI :P"
Lost49
Registered User
Posts: 14
Joined: 14 Aug 2008, 02:00

Post by Lost49 »

Oh I read about this once before.
From what I hear it works pretty well if you don't mind routing your traffic through another companies servers.

I wouldn't recommend it for a company with confidental data but it might be just what you are looking for. :)
Charger14
Registered User
Posts: 302
Joined: 05 Jul 2004, 02:00
Location: In my chair

Post by Charger14 »

Far as I know with Hamachi its only the initial login to their mediation servers that goes through them. Once you logged in you directly connected to the other people in your groups.

Just don't like Hamachi because it tends to be a bit slow at times for some applications. Plus it's somewhat limited in that its a one to one link only, you cant say link an entire branch office to head office.
Is this thing on?Helloooo?
Nuke
Registered User
Posts: 3515
Joined: 28 Feb 2004, 02:00
Processor: Xeon E5620
Motherboard: Asus P6T6 Workstation
Graphics card: MSI GTX770
Memory: 24GB Hynix
Location: ::1

Post by Nuke »

For PPTP it will be 1723
Exept prot 1723 TCP, also protocol 47 forwarding is needed for PPTP. Haven't found many cheap routers being able to do it.

Hamachi is the biggest load of crap Even a SSH sesion is a pain with 2000ms latency.

OpenVPN is a good choice, easy to port forward.

IS it just 2 sites you want to link, or is it a lot of clients to one site?
Image
Charger14
Registered User
Posts: 302
Joined: 05 Jul 2004, 02:00
Location: In my chair

Post by Charger14 »

Its GRE port 47, and majority of routers dont have an option for it. If you have the option for PPTP-VPN under your standard applications then it automatically forwards it accordingly. Failing that just specify the server as a DMZ.
Is this thing on?Helloooo?
Nuke
Registered User
Posts: 3515
Joined: 28 Feb 2004, 02:00
Processor: Xeon E5620
Motherboard: Asus P6T6 Workstation
Graphics card: MSI GTX770
Memory: 24GB Hynix
Location: ::1

Post by Nuke »

GRE is a layer 4 protocol. and its protocol number is 47. Like UDP is 17 and TCP is 6, ICMP is 1 and OSPF is 89. GRE doesn't have ports like TCP and UDP.
Image
douglash
Registered User
Posts: 934
Joined: 07 Jun 2007, 02:00
Location: Durban

Post by douglash »

Nuke wrote:IS it just 2 sites you want to link, or is it a lot of clients to one site?
just 2 sites...
douglash
Registered User
Posts: 934
Joined: 07 Jun 2007, 02:00
Location: Durban

Post by douglash »

Update:

the one site has a Billion router as mentioned before, the other is using iBurst access..

Can i still use OpenVPN for this and will it be secure?
Post Reply