|
|||||||||||
|
Re: linux-ipsec: Any work done on an IPSec masq module?
From: Richard Guy Briggs <rgb(at)conscoop.ottawa.on.ca>
Date: Thu Aug 13 1998 - 15:57:35 EDT
Not directly... > I recently learned that the 2.0.x masq code does not support the BaySecure
Sorry to delay in replying to your original request. I have the same problem here and needed to work out the solution first to be sure it worked. To answer your question, No, you are not obviously wrong. I was able to solve the problem by putting in a ipfwadm rule before the masquerading rule that intercepted any traffic from specific hosts or groups of hosts to the other end of the ipsec tunnel. I was only able to do this in tunnel mode so far, but have not tried transport mode. Since tunnel mode hides the internal address, this is not a problem. In transport mode, you require a valid internet address, in which case you don't need masquerading. > Does anyone care to comment on the usefullness of masq support for IPSec in
I can't quite envision what you are going to do in a ipmasq module to accomplish this. > If all goes well and no one else is already inventing this wheel, myself or
I have tested the above and it works, but the ipfwadm rules must be modified every time you add a new outgoing SPD/SA. Good luck. I will document this at some point. If you need more details, don't hesitate to ask the *list*. Can someone advise this list if anyone has done any masq work wrt. VPNs or IPSEC please.
> Al Youngwerth
slainte mhath, RGB
Richard Guy Briggs -- PGP key available Auto-Free Ottawa! rgb at conscoop dot ottawa dot on dot ca http://www.flora.org/afo/http://www.conscoop.ottawa.on.ca/rgb/ Ottawa-Rideau Bioregion, CanadaPlease send all spam to root@127.0.0.1
"We left our footprints in the Earth
-----BEGIN PGP SIGNATURE-----
iQCVAwUBNdNFLN+sBuIhFagtAQFGLQP+NiiwxX8XsEO1+qZOKxfFFlek8MJjY2Ua
qapFPZBdsjWkkeFnmf92TYaZZ0lQ0DtU7IUVJIstjpCtFQDoqUoDUugWjT1a5PVm
vFqA+O/RV+RAQ7Kb0+9IcW87u97nPicQMZgZAtzgygVbi5Z1s/LSY8LAQJx+C7oD
1QwlauONiuQ=
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 12:59:26 EDT |
||||||||||
|
|||||||||||