Добавил:
Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:
Building And Integrating Virtual Private Networks With Openswan (2006).pdf
Скачиваний:
73
Добавлен:
17.08.2013
Размер:
4.74 Mб
Скачать

Chapter 8

If you do not want to tunnel all traffic through the VPN, you must click the Advanced... button and uncheck the box for Use default gateway on remote network. Do not change any IPsec settings in the Options tab!

When done, click OK until you are back at the main connection window. You can now click Connect. This should bring the L2TP/IPsec connection up, provided you have imported the necessary X.509 Certificates.

If you receive 789 errors, double-check the hostname. If that is not the problem, try using an IP address. If that still gives an error 789, check that the IPsec service is not disabled and stopped.

Apple Mac OS X L2TP Configuration

Configuring L2TP using PSK on Mac OS X is very easy thanks to a nice simple user interface. With Mac OS X 10.4, codenamed Tiger, it should also be possible to use L2TP with X.509 Certificates, although it is not always as straightforward as we might like.

To make things worse, all versions of Mac OS X up to at least version 10.4.3, which is Tiger with all software updates at the point of writing, have a broken NAT-T implementation. Openswan 2.4.5 has a workaround to correctly interoperate with the broken NAT-T implementation of Tiger.

All versions of Mac OS X up to 10.4.3 (Tiger) have a broken NAT-T implementation. Openswan 2.4.1 has a workaround for this problem, but this workaround doesn't always work yet. Hopefully the workaround will work in all cases in Openswan 2.4.2 or 2.4.3.

To configure a L2TP/IPsec VPN connection, open the Internet Connect application from the System Preferences menu, or from the wireless menu that appears when you click on the wave icon at the top.

173

Interoperating with Microsoft Windows and Apple Mac OS X

Change the Configuration dropdown from Other to Edit Configuration. A new window will open to configure your connection.

Fill in Description and Server Address. Fill in Account Name and for User Authentication select Password and fill in the password. At the Machine Authentication section, select Shared Secret and type in the PSK.

You can select Enable VPN on demand and then click the Options... button to add domains and host names. If you then cause a DNS lookup for any of these domains or host names, you will trigger the VPN connection.

One important option is not part of the VPN connection settings. If you don't want to use the VPN as default route to the Internet when you are using Tiger, you need to go to Internet Connect's main menu bar and select Connect and then Options. A new window will appear where you can remove the check from Send all traffic over VPN connection.

174