[c-nsp] Slackware Linux via 3002 VPN Concentrator?

Howard C. Berkowitz hcb at gettcomm.com
Thu Sep 22 14:20:47 EDT 2005


I'm having difficulty getting a PC running Slackware Linux to telnet 
through a 3002-3005 VPN (and then to a 3640 reverse telnet server). 
The same PC, running Windows and using 3002 defaults, telnets there 
just fine, as does a Cisco VPN client under Mac OS X.

We had earlier problems with the Slackware box doing wget and plain 
http to a server on the remote VPN. To get that to work, we set 
addresses statically on the PC and 3002.  We did so because Slackware 
had problems with DHCP defaults: the 3002, not knowing the location 
of a DNS server, put its own address in the DHCP DNS field. On 
receiving the DHCP response, Slackware decided it needed to know its 
own name, so it immediately started sending reverse DNS requests to 
what it thought was the DNS server, even though it had no particular 
reason to look for its own name.

In addition, once we went to static configuration, we needed to set 
up an /etc/hosts.txt files giving a few key addresses, and set the 
resolver to try this local file first. It was also necessary to set 
the MTU to go through IPsec, and we used 1400.

A protocol analyzer on the PC-3002 Ethernet shows TCP handshakes and 
pings going out, but they are not reaching the destination. Given 
that the same dual-boot PC works fine in Windows with DHCP, the 
problem, pretty clearly, is between the 3002 and the PC.  If I 
statically configure the local address, default gateway, and DNS 
server in the PC under Windows, however, I can't telnet or ping.

Any thoughts?


More information about the cisco-nsp mailing list