[Openswan Users] ipsec with xl2tpd

Paul Wouters paul at xelerance.com
Tue Nov 18 17:43:06 EST 2008


On Tue, 18 Nov 2008, Reza Issany wrote:

> I have try to patch the kernel using make nattpatch, but impossible to patch
> in 2.6.25. I've successfully patch a 2.6.18 kernel, but any of 2.6.2x kernel
> could be patch ?!

There is a patch for 2.6.23 on the ftp server. We have not tried newer ones
yet, the patch might need small modifications.

> In windows, I've creted a VPN connection using the public address of the
> openswan server,
> choosing VPN IPSEC / L2TP and puting the user in chap-secrets.

Did you disable the "l2tp encryption" that windows turns on per default
 and clicked on the bogus "you want no encryption" window?
Did you change type from "auto" to "L2TP VPN"?

> Why have I to exclude the 192.168.10.0 network ?

You cannot accept that range behind the same NAT, because you are using
that range behind your server. The NAT-T tunnel uses the internal IP of
your client.

> I'd like to patch my currently kernel, but I can't find any patch for that
> kernel.

We have not had the resources to look at the changes needed.

Paul

Paul


More information about the Users mailing list