News: This forum is now permanently frozen.
Pages: [1]
Topic: Only 1 VPN outoging connection allowed at a time?  (Read 3994 times)
« on: March 28, 2007, 05:27:31 »
gshipp *
Posts: 1

This may be a silly question but is there any reason why monowall only allows 1 passthrough outgoing VPN at a time? (IPSec/PPTP).

I have 3 Windows PC's on my network and only 1 of them can make a VPN passthrough connection at a time to a server on the Internet.
« Reply #1 on: March 28, 2007, 17:03:53 »
jreineri *
Posts: 6

Are all three PC attempting to establish a connection to the same machine?  If so could it  be the target machine not making the connection because it sees all three conections as coming from the same IP address, the public address of your m0n0wall?  I am no expert, so I welcome any explanation if this is wrong.
Good luck
Jim


« Reply #2 on: March 29, 2007, 01:34:26 »
falcor *
Posts: 17

Probably has to do with not using ICMP/UDP but rather ESM or another protocol service.  In order to do it with many behind the same NAT you will need to have the server and client use ICMP/UDP.  This generally effects hosts connecting to the same server.  You could alrernativly work around the VPN provider's shortcomings by setting up a 1:1 NAT for each of the machines... or best possible solution is to open a site to site IPSEC VPN using the m0n0wall and then all the machines would be on the VPN.

Hard to say without knowing more data on the setup.
« Reply #3 on: March 31, 2007, 05:03:01 »
darklogic *
Posts: 45

I believe it is limitations on PPTP port 1723 with GRE and all connections coming from the same public IP being you firewalls WAN interface.
« Reply #4 on: March 31, 2007, 20:17:01 »
cmb *****
Posts: 851

This is a known limitation with PPTP because of limitations in NAT'ing GRE in ipfilter. IPsec shouldn't be a problem, I connect multiple machines to the same IPsec VPN endpoint all the time with no problems.
 
Pages: [1]
 
 
Powered by SMF 1.1.20 | SMF © 2013, Simple Machines