Broadband-Hamnet™ Forum :: General
Welcome Guest   [Register]  [Login]
«StartPrev123456NextEnd»
 Subject :Re:Re:Re:Virtual Tunnels.. 2014-10-15- 21:12:47 
SM7I
Member
Joined: 2012-04-30- 14:56:55
Posts: 79
Location: JO65mo
 

In Sweden we have now, on trial, installed the Racoon IPSec VPN server on our gateway, which makes it possible to connect to the BBHN/HSMM/AMPRnet network behind the gateway using a regular client such as iPhone, Windows, Mac, Linux or whatever.


This gives the opportunety to do a real live demo, among other things, from your clubhouse or such.


We have also connected to a large BBHN network based in New Mexico US, also one node in Barcelona Spain is connected.

 

We are happy to announce that the system is very stable and reliable.

IP Logged
Last Edited On: 2014-10-15- 21:18:44 By SM7I for the Reason
IT infrastructure and security professional
 Subject :Re:Re:Re:Re:Virtual Tunnels.. 2014-10-15- 21:22:05 
KF5JIM
Future Astronaut
Joined: 2013-07-17- 12:13:36
Posts: 250
Location: Nederland
Running a VPN Server myself, I agree that method SM7I has mentioned is a valuable method to have in your toolbox. (Greetings from the Netherlands, SM7I! I'd enjoy traveling to Sweden to see and learn about your setup.)
IP Logged
My opinions and views expressed here are solely my own.
 Subject :Re:Re:Re:Re:Virtual Tunnels.. 2014-10-15- 21:23:24 
SM7I
Member
Joined: 2012-04-30- 14:56:55
Posts: 79
Location: JO65mo
 
KF5JIM, you are always welcome. Just contact me if you want to meet !
IP Logged
IT infrastructure and security professional
 Subject :Re:Re:Re:Re:Virtual Tunnels.. 2014-10-16- 03:09:55 
k5dlq
Member
Joined: 2012-05-11- 08:05:13
Posts: 233
Location: Magnolia, TX USA
 
Interesting. I suppose I could also build an OpenVPN server on a RaspPi with HSMM-Pi and accomplish something similar. Thinking out loud... Wondering if this may be a more secure solution and reduce the security vulnerabilities with routing tunneled traffic out the WAN interface and onto a private lan (home network)?
IP Logged
Darryl - K5DLQ
www.aredn.org
 Subject :Re:Virtual Tunnels.. 2014-10-16- 09:28:18 
EB5JEQ
Member
Joined: 2013-09-21- 14:11:41
Posts: 8
Location: Elche Alicante Spain
 

Hi:

today by first time, I see the neighbour stations from USA in my station.

I am seeing The  Swedish stations ok, about 3 weeks,  

I suppose that Johan SM7I, has completed the link to the USA network.

Excelent work, Johan, thanks for your help!!

The router now is in test phase in my shack, in a few days I will  mount in the roof on the mast reserved for this with a onmi 6 dbs antenna, and put the 2,4 ghz signal in my area.

I wait that other Spanish hams will connect in a future.

node name : http;//eb5jeq-24:8080

73s.


Miguel EB5JEQ www.eb5jeq.es



IP Logged
 Subject :Re:Re:Re:Re:Virtual Tunnels.. 2014-10-16- 10:15:02 
SM7I
Member
Joined: 2012-04-30- 14:56:55
Posts: 79
Location: JO65mo
 
Hi Miguel ! Thank you my friend. Now we hope that more spanish stations will emerge !
IP Logged
IT infrastructure and security professional
 Subject :Re:Re:Re:Re:Virtual Tunnels.. 2014-10-23- 04:48:35 
VA7WPN
Member
Joined: 2013-04-29- 12:21:43
Posts: 60
Location: BC, Canada
 
Good afternoon, Its been a while for me... Iv moved across the conteinent. Is it possible for a little tutorial on how you have your VPN setup, and if there is a common system HSMM-MESH users are using? Also... Is anyone testing the VOIP over this yet?
IP Logged
 Subject :Re:Re:Re:Re:Virtual Tunnels.. 2014-10-23- 05:07:31 
SM7I
Member
Joined: 2012-04-30- 14:56:55
Posts: 79
Location: JO65mo
 

VA3WPN


There are two known VPN solutions as of today, the GRE solution and the VTUN solution.


Both of them has their pros and cons, but in the end it´s up to you and your environment to choose which one is the most suitable.


Also, there are no issues in combining the two solutions, but it requires a hubsoftware. It´s also possible to combine networks of different HSBB / BBHN firmware-versions using hubsoftware, however there´s a slight handjob to be done on the 0.4.3 nodes in order for this to work. No big deal actually.


Yes, VoIP is being used widely over HSMM / BBHN networks and our (SM) network uses this traversing VPN without any issues.


You can have a look at our (SM) hub at http://44.140.236.17:8080


If you need details on the GRE solution please drop me an email and I´ll send you the documents.

IP Logged
Last Edited On: 2014-10-23- 05:09:30 By SM7I for the Reason
IT infrastructure and security professional
 Subject :Re:Re:Re:Re:Virtual Tunnels.. 2014-10-23- 06:05:44 
VA7WPN
Member
Joined: 2013-04-29- 12:21:43
Posts: 60
Location: BC, Canada
 
Thank you, Im going to try this out tonight, maybe this weekend if its raining and I can't get out and hunt.
IP Logged
 Subject :Re:Re:Re:Re:Virtual Tunnels.. 2014-10-23- 06:24:17 
k5dlq
Member
Joined: 2012-05-11- 08:05:13
Posts: 233
Location: Magnolia, TX USA
 

Hi guys. Need some assistance/guidance on this...
I have followed K5KTF's instructions to install the vtun server on my 54GS. I am seeing two issues:

1) It appears that the firewall is blocking connections from the WAN to vtun. If I disable the firewall (/etc/init.d/firewall stop), i do see successful connections to vtund.

2) Even though these connections are successful to vtund, it looks like OLSRD is not aware of them. ie. no new routes are established in olsrd status pages and no "remote" nodes are appearing.

I have verified that the "iptables -A FORWARD -i eth0.0 -o tun+ -j ACCEPT" commands are in the /etc/init.d/firewall file as described.
I have added the tun interfaces to the /etc/config/olsrd.conf file (and config.mesh file)
I have double checked the vtundsrv.conf file client entries to contain the proper interface "up" commands and addresses.

Any advice, troubleshooting tips?

Thanks, K5DLQ - Darryl

IP Logged
Last Edited On: 2014-10-23- 06:42:30 By k5dlq for the Reason
Darryl - K5DLQ
www.aredn.org
 Subject :Re:Re:Re:Re:Virtual Tunnels.. 2014-10-23- 15:48:13 
VA7WPN
Member
Joined: 2013-04-29- 12:21:43
Posts: 60
Location: BC, Canada
 
I cant seem to connect to http://44.140.236.17:8080, My browser times out.
IP Logged
 Subject :Re:Virtual Tunnels.. 2014-10-23- 16:54:33 
KG6JEI
Member
Joined: 2013-12-02- 19:52:05
Posts: 516
Location

Daryl:

start at the simple parts, verify ping , verify olsr packets being recieved and transmitted (tcpdump) etx on the interface first and work your way up.  

OLSR has to have the data before routing can become a question and so on so work the issue from the bottom up or top down on each item.

IP Logged
Note: Most posts submitted from iPhone
 Subject :Re:Virtual Tunnels.. 2014-10-23- 21:14:02 
SM7I
Member
Joined: 2012-04-30- 14:56:55
Posts: 79
Location: JO65mo
 

VA3WPN


Try again, there was a slight routingissue, but it´s taken care of now.

IP Logged
Last Edited On: 2014-10-23- 21:14:31 By SM7I for the Reason
IT infrastructure and security professional
 Subject :Re:Re:Re:Re:Virtual Tunnels.. 2014-10-24- 05:17:33 
k5dlq
Member
Joined: 2012-05-11- 08:05:13
Posts: 233
Location: Magnolia, TX USA
 

Ok.
Further troubleshooting...
I can ping from the server to the client.
when i run tcpdump on the tun1 interface, i am seeing the following:
16:13:28.450171 IP 172.31.201.253 > 172.31.201.254: ICMP 172.31.201.253 udp port 698 unreachable, length 92 E..pPW..@.=;................E..T..@.@.M..............@cY.8i8.,.. .g...b..... ...

Looks like the OLSRD packets aren't being accepted. (port 698 unreachable).

in my /etc/config/olsrd.conf file, I do have:
Interface "tun1"
{
Ip4Broadcast 172.31.201.253
}

Where would change the config to allow olsr to accept these packets from the tun1 interface?

Thanks, Darryl

IP Logged
Last Edited On: 2014-10-24- 05:18:49 By k5dlq for the Reason
Darryl - K5DLQ
www.aredn.org
 Subject :Re:Re:Re:Re:Virtual Tunnels.. 2014-10-24- 05:56:35 
AE6XE
Member
Joined: 2013-11-05- 00:09:51
Posts: 116
Location
Darryl, If this is UBNT hardware, check out the upload in an earlier post in this thread. I posted a tar file with the /etc/config/firewall settings for all the ports to work. Essentially, clone the dtdlink firewall settings.
IP Logged
 Subject :Re:Re:Re:Re:Virtual Tunnels.. 2014-10-24- 06:02:02 
k5dlq
Member
Joined: 2012-05-11- 08:05:13
Posts: 233
Location: Magnolia, TX USA
 
I running the server on WRT54GSv2. However, I currently have the firewall disabled (/etc/init.d/firewall stop) and still get the port "698 unreachable" coming from my tun1 interface.
IP Logged
Darryl - K5DLQ
www.aredn.org
 Subject :Re:Virtual Tunnels.. 2014-10-24- 06:15:20 
KG6JEI
Member
Joined: 2013-12-02- 19:52:05
Posts: 516
Location

Darryl: 

(Oops while I was typing Joe got to you so I've cleared my comment)

SM7I:

I took a look at your link. I'm concerned about the address space you are using for your VPN service and how it does not match reasonable internet standards.

1.1.1.0/24 is a public address space and should not be used on the mesh nodes without and assigned allocation from APNIC.

The nodes are not configured to block routing 1.1.1.0/24 out to the public internet.  

You may be causing packet leakage by operating in this manner.

APNIC has had serious issues with this http://www.potaroo.net/studies/1slash8/1slash8.pdf

perhaps moving the the 172.31.x.x space BBHN is promoting for VPN's would be wise.

IP Logged
Note: Most posts submitted from iPhone
 Subject :Re:Re:Re:Re:Virtual Tunnels.. 2014-10-24- 06:23:56 
VA7WPN
Member
Joined: 2013-04-29- 12:21:43
Posts: 60
Location: BC, Canada
 
The "http://44.140.236.17:8080" URL worked for me this time, This weekend, Im going to be boxing up a WRT54GS, along with a Ras-Pi, and trying out some of this tunneling, along with voip. I want to find out what we REALY can do with this equipment and tech. Iv been thinking of useing a similar system to monitor wireless Game-Cams where I hunt. Like so I can pull up to the road, flip on my laptop, and download the photos / video's from the AP's. As well as monitor the areas so I know where the animals currently are. Sound like cheating, but will feed my family!
IP Logged
 Subject :Re:Re:Re:Re:Virtual Tunnels.. 2014-10-24- 09:10:46 
k5dlq
Member
Joined: 2012-05-11- 08:05:13
Posts: 233
Location: Magnolia, TX USA
 

thanks Joe.
Ok, I'm taking a different approach... putting the wrt54gs vtun server on hold...

I'm trying on my Bullet M2 now. I followed your instructions for setting up vtund server on a UBNT Bullet M2.

I used your instructions and did the following:
ran opkg commands...
cp vtundsrv.conf after editing it for a new remote client name/pass (the remote client is a Linksys, so, I commented out the compress and encrypt lines as they don't appear to be compatible with UBNT version of vtun)
appended your network to both my /etc/config/network files
appended your firewall to both my /etc/config/firewall files
appended your olsrd to both my /etc/config/olsrd files
cp vtundsrv to init.d and chmod'd it
vtundsrv enabled (verified rc.d symlink)
reboot

Results:
vtund starts upon boot as expected.
i stopped it to run it as a non-daemon.
ran it: vtund -s -n -f /etc/vtundsrv.conf

I get no vtund connections until I issue a '/etc/init.d/firewall reload'
I then see the remote client connect.
I can ping the remote client 172.31.201.253
In olsrd routes page, i see one additional entry:
172.31.201.254 (mid1.K5DLQ-LGS2-DESK) 10.46.103.163 (K5DLQ-LGS2-DESK) 1 1.000 wlan0

BTW, K5DLQ-LGS2-DESK is another one of my RF MESH nodes (not wired).
My vtun server is on K5DLQ-UBM2-100

Could it be the configuration of the remote node causing no olsrd routing updates??

I would love to have someone else try to remote into my server. (begging/grovelling) ;-)

73, Darryl

P.S. I am running the UBM2 thru a Netgear GS105E with vlans configured.

IP Logged
Last Edited On: 2014-10-24- 09:48:43 By k5dlq for the Reason
Darryl - K5DLQ
www.aredn.org
 Subject :Re:Virtual Tunnels.. 2014-10-24- 10:54:16 
k5dlq
Member
Joined: 2012-05-11- 08:05:13
Posts: 233
Location: Magnolia, TX USA
 

Also, a quick follow-on question for Joe (et al)...
Would this configuration work on Linksys (other than ipkg instead of opkg)?
I'm guessing no as the config files look like they are different formats between versions of openWRT.

k5dlq - Darryl

IP Logged
Last Edited On: 2014-10-24- 10:55:03 By k5dlq for the Reason
Darryl - K5DLQ
www.aredn.org
«StartPrev123456NextEnd»
Page # 


Powered by ccBoard


SPONSORED AD: