Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: [Design] how FS is supposed to deal with problems further down the stack

From: Nico Baggus <mlfreeswan(at)noci.xs4all.nl>
Date: Tue Mar 11 2003 - 19:27:05 EST

Appearantly they didn't make it to the list, (or back to until now) So here it is again ,
just my .02

kind regards,
Nico Baggus

On Monday 10 March 2003 14:12, martin f krafft wrote:
>
> subnet ---- host A ---- internet ---- router ---- main host ---- host B

If redesigning please keep the following into mind....

(internet) ----- DSLAM -- ADSL/MDM <1.1.1.1> --- <Internet Address> FS Host - Localnet (192.168.x.x)

This can be setup with routes like :

On the adsl modem: a host route to <internet address> through interface with 1.1.1.1

Do you need help?X

On FS-Host: (assuming the FS host internet interface is eth0)

add route 1.1.1.1/32 dev eth0
add route default gw 1.1.1.1 dev eth0

ALL the ipsec routes should then be added with

        route add -net <net>/<mask> dev ipsec0
(!Note without GW).

Also the net/net vs. net/host vs host/host can be solved at the routing layer by specifying that for leaving packets a different interface address should be used
for source. (ip route add ... src 192.168.1.1 , assuming the eth1 has address 192.168.1.1 and the above mentioned example)

kind regards,
Nico Baggus



Design mailing list
Design@lists.freeswan.org
http://lists.freeswan.org/mailman/listinfo/design Received on Tue Mar 11 20:00:46 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 12:59:57 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library