Hi Nick,

Good to actually see the technical reasons for it - I wonder why only the
Nokia bothered making their router work for it.   I'm very constrained in
what can be used - and that is a router at most clients sites - the users
have no expertise, but can manage plug their network cables here and that
other one over there and turn it on. They don't want yet another computer
just to get a connection.

However, we have now purchased one of the Nokia M1122's from Trademe.  Thank
you.

Bryce Stenberg.

-----Original Message-----
From: Nick Rout [mailto:[EMAIL PROTECTED]
Sent: Wednesday, 24 September 2003 12:48 p.m.
To: [EMAIL PROTECTED]
Subject: Re: OT -ADSL router capable of multiple VPN connections to same
s erve r?


this appears to be the tecnical reason:

"Q. I cannot connect from more than one computer at the same time. 

A. PPTP uses protocol GRE (47) for it's tunnel. When two clients behind a
single NAT firewall
connect to the same PPTP server, their source IP address will be
rewritten by their firewall. In this case, the GRE sockets in two
pptpctrl processes will be reading GRE packets from both clients. The
only way to distinguish between those two clients is to filter them by
destination call ID number found in the GRE header. In order for the
client NAT firewall to correctly rewrite the PPTP server's replies,
please check Philip Craig's netfilter pptp helper module available from
the Netfilter CVS server: cvs -d
:pserver:[EMAIL PROTECTED]:/cvspublic login When it asks you for
a password type `cvs' cvs -d
:pserver:[EMAIL PROTECTED]:/cvspublic co
netfilter-extensions/helpers/pptp

It will be integrated in KernelMod, but until then, you'll have to build it
yourself. "


from http://poptop.sourceforge.net/dox/qna.html

do you have alternatives like:

1. using a linux firewall instead of a dumb nat router/modem?
2. use a better vpn like ipsec?

On Wed, 24 Sep 2003 12:06:47 +1200
Bryce Stenberg <[EMAIL PROTECTED]> wrote:


DISCLAIMER:  http://www.hrnz.co.nz/eDisclaimer.htm  

Reply via email to