Home page logo
/

basics logo Security Basics mailing list archives

RE: Free Firewallsolution for a Testlab with multiple Networks and VPN
From: "MARTIN Benoni" <benoni.martin () arcelor com>
Date: Mon, 12 Mar 2007 16:16:45 +0100

Hi,

Maybe you should not ask too much : VPN server on a nix box, no client software on workstations, and all for free ... :)

I think OpenVPN should help you.

Good luck !

PS: IPTables are quite a very weak FW, it does not een filter the application's layer ...

-----Message d'origine-----
De : listbounce () securityfocus com [mailto:listbounce () securityfocus com] De la part de nl () forststrasse27 de
Envoyé : samedi 10 mars 2007 19:46
À : security-basics () securityfocus com
Objet : Free Firewallsolution for a Testlab with multiple Networks and VPN

Hi,

we have currently a Testlab with a 192.168.1.0 net behind an iptables Firewall. Remote Acces is currently done  with a 
ssh-Tunnel to the firewall and then connecting the machines via remote desktop.

Now the Lab will increase with more net’s and more people accessing it.
(some of them should only be able to reach 2 PC’s via Remote Desktop in let’s say the 192.168.2.0 net.)

I’d like to do it the following way:
- Give the firewall more networkcards one for each net.
- Enhancing the IPTables (or replace with another free solution) that the users can connect with Windows L2tP-Ipsec 
connection to the firewall. (I don’t want to install vpntools on the clientside).  Depending on the Username&PW of the 
VPN connection the Clientpc’s will get different IP’s in the Testlabnet. User A will get 192.168.1.100 and User B 
192.168.2.100.
- For the Users who only should reach 2 PC’s I think it’s sufficient that they only get Username&PW for the Remote 
desktop access.

As I am new to that stuff:
Can I do this with Iptables/Linux? What tools will I have to install for the VPN connection from Windowsclients on the 
Firewall? Is there a Howto? ;-)


I know with the Astaro Firewall I could do this and I would have a nice & easy interface.. but iam not allowed to spent 
money… Is there comparable freeware?



Thanks for your help!
Regards Tom
 


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]