If your company is using the Contivity Servers (Aka CES's), FreeS/WAN cannot
be used as an end-user client, as it currently doesn't support
Username/Password (let alone SecureID) authentication. It can be make to
work as a branch-office tunnel, however this requires configuration on the
server side of things.
However, if you visit Nortel's website, you'll see there's now a Contivity
Client for most Unixes, and Linux available. It's not free (I believe it's
$100 US) but it seems to work (At least w/RH7.2, it locks RH 7.3's stock
kernel), and it's supported by Nortel (www.netlock.com people seem to be
the ones who wrote it, for those interested).
I'm in the process of doing an in depth eval on it (I bought both Unix +
MacOS licenses for my users here) so I'll probably post a summary of my
experiences in here (tho it isn't FreeS/WAN related) while I'm up at OLS.
Note: I don't work for Nortel (or Netlock) but I've been using the
Contivities for a few years without problems.
Ken Bantoft
kbantoft_at_mdsp.com
> -----Original Message-----
> From: Sam Sgro [mailto:sam_at_freeswan.org]
> Sent: Wednesday, May 29, 2002 2:20 PM
> To: Sebastian Mierswa
> Cc: users_at_lists.freeswan.org
> Subject: Re: [Users] Help with Contivity client
>
>
>
> *** PGP Signature Status: good
> *** Signer: Sam Sgro <sam_at_freeswan.org> (Invalid)
> *** Signed: 5/29/2002 2:19:33 PM
> *** Verified: 5/29/2002 3:10:51 PM
> *** BEGIN PGP VERIFIED MESSAGE ***
>
>
> On Wed, 29 May 2002, Sebastian Mierswa wrote:
>
> > I am desperatly trying to connect to my company network
> from at home. Here
> > ist my configuration:
> > Linux 2.2.16 German SuSe Distribution
> > Client PC Windows 2000 running a Nortel Contivity Client
> with RSA SecurID
> > German T-DSL
>
> You need to better define your problem before we can help you.
>
> Your company's network is running Linux, or Windows 2000
> client? Has your
> company provided you any information on how to connect to
> their network?
>
> The means by which you connect to the internet is not at issue - DSL,
> dial-up, etc won't matter, as long as you can establish an internet
> connection. What is relevant is your network setup at home. Do you
> have a dynamic IP address, or static? Do you use Network Address
> Translation or masquerading, for example?
>
> See doc/config.html for configuration examples, and
> doc/interop.html for
> instructions on how to connect FreeS/WAN to different VPN clients.
>
> Sam Sgro
> sam_at_freeswan.org
>
>
> *** END PGP VERIFIED MESSAGE ***
>
> _______________________________________________
> Users mailing list
> Users_at_lists.freeswan.org
> http://lists.freeswan.org/mailman/listinfo/users
>
_______________________________________________
Users mailing list
Users_at_lists.freeswan.org
http://lists.freeswan.org/mailman/listinfo/users
This archive was generated by hypermail 2.1.3 : Mon Jul 29 2002 - 05:20:08 CEST