|
From: Bradley A. <st...@tu...> - 2003-03-16 03:22:10
|
This question is not an issue with openvpn, per se, but related because openvpn is my weapon of choice. :) I have a network in my home, call it 192.168.0.0/24, with a gateway to the internet of .4. I also have two laptops, a Toshiba Tecra 8100 with a Cisco wireless card, and a Mac Powerbook G3 with an Airport card. I have gotten the two cards talking, now it is a matter of setting up the networking piece of the puzzle. I decided that since 802.11 has enough security issues to make me very uncomfortable with its general use, and since both the Mac and the Toshiba (as well as the bulk of the rest of the network) run Linux, I would set up an IPtables firewall on each wireless interface (eth1) and run openvpn across the ether. What I'm looking for is as transparent as possible access for the roaming laptop (usually the Mac, since the batteries on the Tecra suck), as if it were connected to the wired LAN. Given that the wired LAN is 192.168.0.0/24, I made the wireless LAN 192.168.1.0/30. This gives me two addresses required for the point-to-point link. I got this far, but did not get to the point of setting up the openvpn. I was able to "double-hop" to the wired network from the roaming laptop (e.g. ssh to the wired lappy, then ssh to, say, the mail server). What would be the best way to make it as transparent as possible to get the roaming laptop to be able to access both local services (dns, mail, etc) as well as being able to get it out to the Net as if it were on the wired LAN? thanks, -- --Brad ============================================================================ Bradley M. Alexander | Debian Developer, Security Engineer | storm [at] tux.org Debian/GNU Linux Developer | storm [at] debian.org ============================================================================ Key fingerprints: DSA 0x54434E65: 37F6 BCA6 621D 920C E02E E3C8 73B2 C019 5443 4E65 RSA 0xC3BCBA91: 3F 0E 26 C1 90 14 AD 0A C8 9C F0 93 75 A0 01 34 ============================================================================ Only a government that is afraid of it's citizens try to control them. |