Christopher Juckins

SysAdmin Tips, Tricks and other Software Tools

User Tools

Site Tools


vpn_notes

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
Last revisionBoth sides next revision
vpn_notes [2013/09/25 16:35] juckinsvpn_notes [2015/03/17 13:44] juckins
Line 46: Line 46:
  
 Enter all the appropriate settings as given by work and then __reboot the machine__ otherwise your configuration will not save and you will get an error "no valid VPN secrets". Enter all the appropriate settings as given by work and then __reboot the machine__ otherwise your configuration will not save and you will get an error "no valid VPN secrets".
 +
 +----
 +
 +To connect to a Cisco AnyConnect VPN server, use openconnect as listed above.  Reboot the computer after installing the VPN packages and set up the connection entering the IP address for the Gateway.  
 +
 +----
 +
 +The ntpd service may not be able to connect to time servers; remember to update /etc/ntp.conf and possible /etc/ntp/step-tickers with time sources that are reachable when the machine has the VPN connected.
 +
 +----
 +
 +[[http://www.debuntu.org/how-to-connect-to-a-cisco-vpn-with-vpnc/ Cisco VPN with VPNC (Ubuntu and Debian)]]
 +
 +----
 +
 +Notes from Scalio:
 +
 +  * Install the vpnc rpm and any dependencies, if not already installed.
 +  * As root, use visudo to add the following entries to the sudoers file without the surrounding "<>":
 +
 +        <your user name>   ALL=(root) NOPASSWD: /usr/sbin/vpnc
 +        <your user name>   ALL=(root) NOPASSWD: /usr/sbin/vpnc-disconnect
 +
 +  * As root, create a vpn configuration file (I called mine myvpn.conf) in /etc/vpnc containing the following:
 +
 +        IPSec gateway XXX.XXX.XXX.XXX
 +        IPSec ID XXX
 +        IPSec secret XXXXXXXXX
 +        Xauth username <your user name>
 +        Xauth password <your password>
 +
 +  * Change file permissions on your vpnc configuration file to 600.
 +  * Copy the two attached files to some place in your path.  I put them in ~/bin.  Make sure you they both have execute permission.
 +  * Use the scripts to start/stop VPN sessions.  I use this from inside a VirtualBox Linux guest.  Occasionally, your vpn sessions will terminate without any notification.  If you aren't getting a response from an established session, you can just do "start_vpnc" again and you shouldn't even get kicked out of any remote terminal sessions you have running.
 +
 +<code>
 +#!/bin/bash
 +# start_vpnc.bash
 +sudo /usr/sbin/vpnc --natt-mode cisco-udp awips
 +
 +
 +#!/bin/bash
 +# stop_vpnc.bash
 +sudo /usr/sbin/vpnc-disconnect
 +</code>
  
 ---- ----
Line 57: Line 102:
   * [[http://pkgs.repoforge.org/kvpnc/]]   * [[http://pkgs.repoforge.org/kvpnc/]]
  
----- 
- 
-To connect to a Cisco AnyConnect VPN server, use openconnect as listed above.  Reboot the computer after installing the VPN packages and set up the connection entering the IP address for the Gateway.   
  
vpn_notes.txt · Last modified: 2015/03/17 13:44 by juckins