|
|||||||||||
|
Re: linux-ipsec: Any work done on an IPSec masq module?
From: Paul Gilbert <pgilbert(at)bank-banque-canada.ca>
Date: Fri Aug 14 1998 - 10:52:54 EDT
I am a somewhat casual observer of the linux-ipsec list. This seems to be a question about the usefulness of something I want to do and I think will be a fairly common use for IPSec, but please excuse me if I am completely confused. (I tried to refresh my memory by looking for a page I once saw describing the difference between tunnel mode and transport mode, but can no longer find it.) If someone can explain all this in terms a novice can understand then I would very much appreciate it. In any event, let me explain the potential application which I hope is, or will be, possible with IPSec and Masq. {home net} <--> [IPMasq] <--> internet<--> [firewall] <-->{secure net} [1st home machine]<===================> [firewall][2nd home machine]<-------> internet
I don't want to prevent other home machines from continuing to connect to the Internet, but I especially would not want any of the home machines to compromise the security of the secure net. This might be a problem if, for example, the tunnel was established between the IPMasq machine and the firewall and one of the other home machines could dial-out to the Internet separately from the IPMasq connection. (And in any event, it seems this IPMasq==firewall tunnel would also have to prevent other home machines from normal connections to the Internet or else security may be compromised.) If necessary, another possible setup would be: {home net2} <--> [IPMasq2] <-->{home net1} <--> [IPMasq1] <--
-->internet<-->
[firewall] <-->{secure net}
[IPMasq2] <==============> [firewall]
and I guess the IPMasq2 machine would not necessarily need to do masquerading but could be a more traditional firewall. Paul Gilbert Received on Fri Aug 14 12:03:57 1998 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 12:59:26 EDT |
||||||||||
|
|||||||||||