forums.xandros.com Forum Index forums.xandros.com
Xandros User Forums
 
 FAQFAQ   SearchSearch   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

A Xandros VPN Server on a Windows AD Network - It works!!

 
Post new topic   Reply to topic    forums.xandros.com Forum Index -> Xandros Server - Software
View previous topic :: View next topic  
Author Message
BNovak
Xplorer


Joined: 11 Aug 2006
Posts: 41

PostPosted: Wed Jan 24, 2007 11:45 am    Post subject: A Xandros VPN Server on a Windows AD Network - It works!! Reply with quote

I seem to remember a thread (although I can't find it now) that stated that there were problems using a Xandros server to accept VPN connections from the Internet and validate the name/passwords against a Windows active directory domain. I tried this and it does work. If anyone needs step by step details, I can erase the drive I used and do it again while recording the detailed information.

The general steps were:

1 Use a computer with 2 network cards, one connected to the local network and one connected to the Internet.
2. Install Xandros Server including the firewall, VPN, and routing servers.
3. Assign fixed I/P addresses to both cards on the appropriate networks during installation.
4. Join the domain properly. This is the pain in the butt part since Xandros does not properly detect the existence of the domain during installation, but the topic has been covered in other threads here. I created a share just to verify that the Xandros server would see the active directory users as a test at this point.
5. Configure and start the firewall.
6. Go to the routing server and check the box to allow routing between network interfaces. (Not certain if this is required but it seemed like a good idea at the time) Very Happy
7. Configure the VPN settings in the VPN server module.
8. Go back to the firewall and allow the VPN access to the local network under defaults/through traffic.

That's it. I connected to the VPN from a notebook with a dial-up internet connection using an account that existed only in active directory and started Outlook. I was able to get the e-mail with no problems. As a side note, the Root account cannot connect since it does not exist in active directory. And any account that is used to connect must have allow dial up enabled in active directory. If anyone needs details on this process, please post here.

Thanks,
Bill
Back to top
View user's profile Send private message
Gman8845
Xandrosianling
Xandrosianling


Joined: 16 Oct 2005
Posts: 294
Location: Central NY, United States

PostPosted: Fri Jan 26, 2007 6:30 am    Post subject: Reply with quote

BNovak,

Glad to hear you were successful. I'd like to know what OS was the client used for the connection? It appears (Outlook) that it was Windows, I was wondering if Xandros Desktop would connect as well.

Just a thought.
Have a great day!
_________________
Running on many systems, multi booting up to 5 Linux OSs on a demo machine, started when it was Coral Linux. Need to know more; just ask.
"I'm just a squirrel, Trying to get a nut!!"
Back to top
View user's profile Send private message
BNovak
Xplorer


Joined: 11 Aug 2006
Posts: 41

PostPosted: Fri Jan 26, 2007 7:25 am    Post subject: Reply with quote

The client was Windows 2000.

The network is a Windows 2000 domain, active directory based network, running in native mode. All of the clients are either Windows 2000 or Windows XP.

Unfortunately I can't use Xandros as a client since there are just too many Windows programs (especially ODBC drivers) that won't work with it. Hmmm.... In order to test it, I'd need Xandros client on a computer with a modem so I could connect from "outside" of the network.... I'd have to swap hard drives in a spare computer and install Xandros. Perhaps I'll try that next week if I have the time.

Bill
Back to top
View user's profile Send private message
juanfermin
Xplorer


Joined: 06 Feb 2005
Posts: 21
Location: Ft. Lauderdale, FL

PostPosted: Sat Jun 16, 2007 8:44 am    Post subject: Re: A Xandros VPN Server on a Windows AD Network - It works! Reply with quote

BNovak wrote:
.... Join the domain properly. This is the pain in the butt part since Xandros does not properly detect the existence of the domain during installation, but the topic has been covered in other threads here. ....


Could you point me in the right direction, because I'm not able to do this.
Back to top
View user's profile Send private message AIM Address Yahoo Messenger MSN Messenger
juanfermin
Xplorer


Joined: 06 Feb 2005
Posts: 21
Location: Ft. Lauderdale, FL

PostPosted: Tue Mar 04, 2008 10:41 am    Post subject: Xandros and Active Directory Reply with quote

I'm also using Xandros to Authenticate VPN's and it works fairly flawlessly, however, I did have some problems:
#1. Samba shares were not listing users in groups correctly.

The Fix? I found that by changing Authentication to Domain from ADS fixed this issue. Not sure if this is because my AD Server is running in Native Mode.

#2. Files that I imported and wanted to make available to Windows Users, were listed as being owned by root, and I couldn't change it to being owned by the users.

The Fix? the smb.conf file located in /etc/samba/ had to be edited to include the follwoing:
winbind enumerate users = yes
windbind enumerate groups = yes
Back to top
View user's profile Send private message AIM Address Yahoo Messenger MSN Messenger
Display posts from previous:   
Post new topic   Reply to topic    forums.xandros.com Forum Index -> Xandros Server - Software All times are GMT - 5 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB © 2001, 2005 phpBB Group