RE: [leaf-user] Bering uClibc IPSEC VPN issues

2005-10-06 Thread Richard Amerman
Thanks for the pointer Eric, I'm assuming that you indicate this as a possible solution to a high level of trafic or high count of connections, but I doubt this would be the problem for us. We have only 20-30 computers behind this firewall which seems like a fairly low number in the scheme of thi

Re: FW: [leaf-user] Bering uClibc IPSEC VPN issues

2005-10-06 Thread Arne Bernin
On Thu, 2005-10-06 at 13:27 -0700, Richard Amerman wrote: > > -Original Message- > > From: Arne Bernin [mailto:[EMAIL PROTECTED] > > > you might want to use tcpdump for this (well i never used > > snort for that, so i don't know if it is easy to use and gets > > all traffic). If you save

FW: [leaf-user] Bering uClibc IPSEC VPN issues

2005-10-06 Thread Richard Amerman
> -Original Message- > From: Arne Bernin [mailto:[EMAIL PROTECTED] > you might want to use tcpdump for this (well i never used > snort for that, so i don't know if it is easy to use and gets > all traffic). If you save the tcpdump output somewhere you > can use ethereal (on windows or >

RE: [leaf-user] Bering uClibc IPSEC VPN issues

2005-10-06 Thread Arne Bernin
On Thu, 2005-10-06 at 12:56 -0700, Richard Amerman wrote: > Thanks for the reply Arne, > I help if i can ;-) > Everything is masqueraded behind the firewall so we are using Nat-T and > the NetScreen client does seem to be using this. > ok. > When things do not go OK some of the symptoms are tha

RE: [leaf-user] Bering uClibc IPSEC VPN issues

2005-10-06 Thread Eric Spakman
Hello Richard, Not sure if this is your problem, but did you take a look at: http://leaf.sourceforge.net/doc/guide/bucu-conntrack.html Eric > Thanks for the reply Arne, > > >> -Original Message- >> From: Arne Bernin [mailto:[EMAIL PROTECTED] >> > >> I do not really understand what your

RE: [leaf-user] Bering uClibc IPSEC VPN issues

2005-10-06 Thread Richard Amerman
Thanks for the reply Arne, > -Original Message- > From: Arne Bernin [mailto:[EMAIL PROTECTED] > I do not really understand what your Problem is. Maybe you > could explain it a bit more... You have Problems after reboot > or you fix the problems with a reboot ? > You are using standard

Re: [leaf-user] one internet, multiple lan vpn howto?

2005-10-06 Thread Arne Bernin
On Thu, 2005-10-06 at 12:07 +0800, dny wrote: > hi all, > Hi Dny, > i have 4 LAN located at different locations. > all connected using wireless: > > internet > | >router > | > lan1 (192.168.1.xxx) - firewall - wireless (10.11.12.1

RE: [leaf-user] Bering uClibc IPSEC VPN issues

2005-10-06 Thread Richard Amerman
One thing I forgot to mention is that we are using OpenVPN with our firewall as the terminating VPN server (works fantastic). Not sure if it is possible for this configuration to intefer with Host (behind our firewall) to remote VPN gateway communication but thought it would be worth mentioning.

Re: [leaf-user] Bering uClibc IPSEC VPN issues

2005-10-06 Thread Arne Bernin
On Thu, 2005-10-06 at 10:30 -0700, Richard Amerman wrote: Hi Richard ! > It runs great with no issues other then the new VPN issue. > > We have been connecting from PC's inside the firewall to a remote > location running Juniper networks NetScreen and until this week have had > no problems. > >

[leaf-user] Bering uClibc IPSEC VPN issues

2005-10-06 Thread Richard Amerman
We have been running a leaf firewall for about 3 years or more. Most of that time it has been a Bering 1.0 RCx of some kind (can't remember the exact release). We just upgraded to a new machine running Bering uClibc 2.3-rc1 from CF. I built this image using primarily the uClibc ISO image as my bas