Re: VPN project solutions

Lonnie Cumberland <lonnie-ICnRY6A/[email protected]> Sun, 17 Oct 2004 14:53:06 -0500
Newsgroups gmane.comp.security.zebedee.general
Message-ID <[email protected]>
A little more info for you on #1.

What I am actually looking to do is to possibly use Zeb to allow a few 
clients to connect to the server and have all of their ports sent 
through the server. This actually sets us an encrypted virtual private 
network over the internet. The server then can make a connection to 
other servers but all of the client traffic would go through the server 
from the clients.

to visualize this, think of 3 node servers (A,B,C) that have "Start 
Topologies" in which each of their nodes connects creates a tunnel with 
a Client node except for two nodes on each of the servers that connect 
to the other servers. It might look like a triangle with each vertex 
being a server node connected to each other for each side of the 
triangle along with additional client nodes on each vertex.

What do you think?

Thanks,
Lonnie

Magnus Wedberg wrote:

>>1. In OpenVPN, you can assign a masqued IP like 10.0.0.5 and adjust
>>the default gateway of the client so that other internet machines
>>cannot see the client any more. Maybe isolate all of the ports would
>>be how Zebedee does this?
>>    
>>
>
>I don't understand this, sorry :-)
>
>  
>
>>2. I will need for the client machines to be able to accept multiple
>>connections (server mode I guess) and well as being able to make a
>>connection to another server.
>>    
>>
>
>That is no problem -- I am running both in "local" client mode (only 
>listens to connections from localhost, several machines each with 
>their own copy of Zeb connecting to one remote server) and a kind of 
>"gateway" mode (using a separate network card, tunneling all port 139 
>connections from the whole network on that IP to a remote Zeb 
>server).
>
>You can also specify any target in the destination network on the 
>server, so if you have Zeb running on the gateway/firewall (in the 
>destination net) you can tunnel to another server behind the 
>firewall. Or you can port forward the external Zeb port in the 
>firewall to an internal server running the Zebedee program, 
>forwarding to itself or yet another server. It is very flexible in 
>that way, I have used both methods.
>
>  
>
>>3. What about scaling connection limitations of Zebedee?
>>    
>>
>
>I don't know of large scale setups in use... maximum tested for me as 
>of yet is five simultaneous workstations using SMB networking plus 
>IMAP and SMTP over one Zeb gateway. Not a hassle yet (with Zeb, 
>anyway). I use it for quick and dirty road warrior setups but will 
>investigate OpenVPN when I have the time :-P 
> 
>  
>




-------------------------------------------------------
This SF.net email is sponsored by: IT Product Guide on ITManagersJournal
Use IT products in your business? Tell us what you think of them. Give us
Your Opinions, Get Free ThinkGeek Gift Certificates! Click to find out more
http://productguide.itmanagersjournal.com/guidepromo.tmpl