Astaro User Bulletin Board
Go Back   Astaro User Bulletin Board > Closed Forums (read only) > ACC Betas > ACC V2.000 BETA (closed)

Welcome to the Astaro User Bulletin Board.
If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 02-27-2009, 07:26 AM
Senior Member
 
Join Date: Feb 2004
Location: Bielefeld
Posts: 255
Default [1.950] VPN with dynamic Endpoint [FEATURE]

Hi,

i downloaded the Beta yesterday, after updating my first two Firewalls to 7.400 i tried to create a VPN Connection via the ACC. It worked very well! At the moment only RSA is available, will it be possible to use Certs in future?

The problem(maybe not a bug, but a feature) i found is:
One of the devices has an dynamic IP and the other one is static. I created both VPN Endpoints with "initiate connection". On my static gateway i have a definition for the remote gateway with the IP, but this will change in about 24 hours and the vpn will not work.

I just tried it with a "respond only" connection, that works, because it has no IP for the Remote gateway.

Maybe it is possible to determine if the remote gateway is an dynamic ip, or the acc manages the definition of the remote gateway an updates it with the new ip if it changes?

Until now i can say everything alright with this BETA, well done. Creating VPNs is a very nice fetaure!

Now i will go hunting bugs!

regards, mario
Reply With Quote
  #2 (permalink)  
Old 02-27-2009, 03:08 PM
megaposer's Avatar
Scourge of Humanity
 
Join Date: May 2006
Location: Karlsruhe, Germany
Posts: 691
Default

Hi,

thanks for your feature request and your positive feedback on the VPN stuff - we will come back to you soon regarding feasibility.

About the available authentication method types: Currently there are no plans when other schemes like X.509 CERTS or PSK will be supported - definitely not in the final ACC V2 release. My own preference would be to support X.509 in a non-PKI fashion first (just simple re-use of the Certificates which are already there).

One thing: if you set both endpoints to initiate the connection although you have one dynamic endpoint with changing IP, the ACC will know about the changing IP address and propagate this information to the other device which then can readjust its tunnel configuration. So the VPN will work after you get a new IP assigned.

Cheers
__________________
"Molest me not with this pocket calculator stuff."

Last edited by megaposer; 03-02-2009 at 06:40 AM.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 03:12 AM.

 

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.


These pages are specifically maintained for the discussion of firewall issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases. issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases.