Gentoo Archives: gentoo-server

From: Paulo Loureiro <met@××××××.com>
To: gentoo-server@g.o
Subject: Re: [gentoo-server] Frustration with most hardware firewalls, Gentoo VPN
Date: Sat, 04 Oct 2003 15:34:15
Message-Id: 1065281945.6736.9.camel@amee
In Reply to: [gentoo-server] Frustration with most hardware firewalls, Gentoo VPN by "Jonathan S. Romero"
1 Hello Jonathan,
2
3 I've been using several gentoo firewall/servers with OpenVPN for several
4 months without a single problem. I've slightly modified
5 /etc/init.d/openvpn in order to make it work more smoothly, but that's
6 it.
7
8 I've also tried ipsec (freeswan) and althow it's quite stabled, I think
9 OpenVPN is a better choice for a small (<20) number of tunnels (at
10 least until kernel 2.6 is released) since it's not tied to a specific
11 kernel version and allows for more than one tunnel for the same remote
12 network (redundant routes).
13
14 Cheers,
15
16 --- Paulo Loureiro.
17
18
19
20
21 On Sat, 2003-10-04 at 15:00, Jonathan S. Romero wrote:
22 > Hello,
23 >
24 > I have become incredibly disenchanted with hardware firewall/VPN solutions.
25 > Almost every one on the market that I used is a crippled version of something
26 > that could be made from a linux system. The manufacturers also charge
27 > licensing fees for encryption algorithms that are not included by default.
28 >
29 > I for a while thought i had found a cost effective solution with the Netgear
30 > FSV318 VPN router (it has tons of features for vpn), and it was cheap 150$.
31 > But the thing crashes under heavy vpn load and reboots.
32 >
33 > I am thinking about building a new firewall/vpn system with gentoo, does
34 > anyone on this list use two gentoo systems as VPN endpoints?
35 >
36 > -Jonathan S. Romero
37 >