On Tue, 10 Jun 2003, Rene Cunningham wrote:

> On Tue, Jun 10, 2003 at 08:00:52PM +1000, Luke Burton wrote:
> > What I want is a VPN endpoint, running Linux, that can be connected to 
> > with free clients for Windows NT/2000/XP and Mac OS X, and Linux as 
> > well obviously.
> > 
> 
> Check out PPTP. It works well with Windows clients, though i havent come
> across a Mac client. W2K and XP come with decent PPTP support.

It also comes with a half dozen protocol holes.  See Bruce Schneier's
analysis of the protocol (I don't have the URL to hand, but google should
turn it up).

> > Freeswan seems the obvious solution, but there is little docco to 
> > indicate how I configure it for maximum interoperability. Let alone 
> > interop with other free software.

The FreeSWAN docs are quite complete.  I got IPSec running pretty quick. 
Time delays were due to my fsckups, not the software or documentation's
fault.

The docs that come off the FreeSWAN site tend to be swan-to-swan centric,
but none of the information is swan-specific.  The one gotcha is that 2K/XP
clients only implement X.509 key management, which needs a patch to FreeSWAN
(the Debian versions have the patches pre-applied).  Another Microsoft
"we'll do things our way and f**k the rest of you" idea.


-- 
-----------------------------------------------------------------------
#include <disclaimer.h>
Matthew Palmer, Geek In Residence
http://ieee.uow.edu.au/~mjp16


-- 
SLUG - Sydney Linux User's Group - http://slug.org.au/
More Info: http://lists.slug.org.au/listinfo/slug

Reply via email to