[c-nsp] Slackware Linux via 3002 VPN Concentrator?
Howard C. Berkowitz
hcb at gettcomm.com
Thu Sep 22 14:20:47 EDT 2005
I'm having difficulty getting a PC running Slackware Linux to telnet
through a 3002-3005 VPN (and then to a 3640 reverse telnet server).
The same PC, running Windows and using 3002 defaults, telnets there
just fine, as does a Cisco VPN client under Mac OS X.
We had earlier problems with the Slackware box doing wget and plain
http to a server on the remote VPN. To get that to work, we set
addresses statically on the PC and 3002. We did so because Slackware
had problems with DHCP defaults: the 3002, not knowing the location
of a DNS server, put its own address in the DHCP DNS field. On
receiving the DHCP response, Slackware decided it needed to know its
own name, so it immediately started sending reverse DNS requests to
what it thought was the DNS server, even though it had no particular
reason to look for its own name.
In addition, once we went to static configuration, we needed to set
up an /etc/hosts.txt files giving a few key addresses, and set the
resolver to try this local file first. It was also necessary to set
the MTU to go through IPsec, and we used 1400.
A protocol analyzer on the PC-3002 Ethernet shows TCP handshakes and
pings going out, but they are not reaching the destination. Given
that the same dual-boot PC works fine in Windows with DHCP, the
problem, pretty clearly, is between the 3002 and the PC. If I
statically configure the local address, default gateway, and DNS
server in the PC under Windows, however, I can't telnet or ping.
Any thoughts?
More information about the cisco-nsp
mailing list