OpenVZ Forum


Home » General » Support » IPSec-Server in a VPS
IPSec-Server in a VPS [message #28324] Thu, 13 March 2008 23:31 Go to next message
schogge is currently offline  schogge
Messages: 19
Registered: July 2007
Junior Member
Hi all,

I would like to install a VPN-Server inside a VPS. Is that supported and if so, what needs to be done?

The wiki is talking about installing an IPSec-Client (vpnc) and also OpenVPN-Server. But I want to use an IPSec-Server like Openswan or racoon.

Thanks
schogge
Re: IPSec-Server in a VPS [message #28451 is a reply to message #28324] Tue, 18 March 2008 15:06 Go to previous messageGo to next message
schogge is currently offline  schogge
Messages: 19
Registered: July 2007
Junior Member
No one ever tried?

If it is not possible to set up an IPSec-Server in a VPS, this info would save me a lot of time.

So if anybody knows....
Re: IPSec-Server in a VPS [message #35891 is a reply to message #28451] Wed, 29 April 2009 12:42 Go to previous messageGo to next message
perkimon is currently offline  perkimon
Messages: 2
Registered: April 2009
Location: UK
Junior Member
Hi,

I'm going to attempt this too. Inside a container preferably then if that fails I'll provide a VPN on the host node and allow the container access some how.

Did you get this to work?

Cheers
Re: IPSec-Server in a VPS [message #35893 is a reply to message #28324] Wed, 29 April 2009 13:15 Go to previous messageGo to next message
schogge is currently offline  schogge
Messages: 19
Registered: July 2007
Junior Member
Unfortunately no. I also thougt about doing VPN on the host. But I don't like that.

If you want to do VPN on the host at least your kernel has to support it but not the virtualization system. So I think this should be possible (with the right kernel).

I decided to buy a separate VPN Router.
Re: IPSec-Server in a VPS [message #35923 is a reply to message #35893] Thu, 30 April 2009 16:49 Go to previous messageGo to next message
perkimon is currently offline  perkimon
Messages: 2
Registered: April 2009
Location: UK
Junior Member
Ok,

I'll have a poke and see if I can get one of my containers to do it... I'd like to save on actual physical hardware because i can provision a container based VPN from where ever I am, ie don't have to go to the data center to plug it in.

Cheers
Re: IPSec-Server in a VPS [message #37207 is a reply to message #28324] Wed, 26 August 2009 11:28 Go to previous messageGo to next message
groka76 is currently offline  groka76
Messages: 1
Registered: August 2009
Junior Member
Hi All,



I have work out configruation with Racoon.
The other side have CISCO PIX 6.
The Racoon is installed in the host machine and send packet in the containter.
It needed set up a veth interface.


Ga
Re: IPSec-Server in a VPS [message #43027 is a reply to message #37207] Mon, 04 July 2011 14:42 Go to previous message
JohnDoe is currently offline  JohnDoe
Messages: 3
Registered: July 2011
Junior Member
groka76 wrote on Wed, 26 August 2009 13:28
Hi All,

I have work out configruation with Racoon.
...
The Racoon is installed in the host machine and send packet in the containter.
It needed set up a veth interface.
Ga


Hi groka76,

how did you achieve that? I also tried such scenario, but my packets always get dropped or didn't reach the VPS.

I have a openVZ host running racoon. I can establish a connection and the vpn client can ping the host's virtual bridge vmbr1 IP 10.0.2.254. But I can't reach/ping the VPS "behind" the virtual bridge with IP 10.0.2.123.
on "tcpdump -i eth0" in the VPS I can see the ICMP request, but there is no reply generated.
If I enter the VPS and ping the VPN client on 192.168.100.101 the ICMP packets are tunneled. I can see them on the VPN client with wireshark. A ICMP reply is generated, passes the tunnel and I can see it on the virtual bridge vmbr1 on the host ("tcpdump -i vmbr1") and inside the VPS ("tcpdump -i eth0"), but the ICMP replies got ignored or dropped?!?! --> no messages and 100% packet loss in the end.


best regards,
JD
Previous Topic: problems with second container and venet
Next Topic: VE not reachable via ipsec-Tunnel using openswan and bridge-devices
Goto Forum:
  


Current Time: Fri Aug 16 18:39:06 GMT 2024

Total time taken to generate the page: 0.02984 seconds