|
|||||||||||
|
Re: [Design] letting traffic flow through a SG by default
From: Michael Richardson <mcr(at)sandelman.ottawa.on.ca>
Date: Wed Mar 12 2003 - 23:03:54 EST
Sam> (Caveat: If I make an erroneous assumption about OE's method of Sam> negotiation, please correct me.) Not about OE, but rather, about what packetdefault=pass does.
Sam> Imagine this scenario: I've got a gateway running FreeS/WAN,
Sam> configured
Sam> with a few VPN conns. If that gateway were configured to do OE only
Sam> for
Sam> itself, a malicious hacker could negotiate an OE connection with it,
Sam> and then
Sam> pass packets intended for the subnet behind down the tunnel.
To get completed, we need to have pluto express the SAref that it got from KLIPS to the updown and firewall scripts, so that they can configure things. This is partially dependant upon the advanced routing _updown script.
Sam> I believe the security concerns raised in employing
Sam> packetdefault=pass by
Sam> default nix this as a solution.
No, there is really no affect.
Sam> For OE, we have chosen to direct *all* packets, regardless of
Sam> source or
Sam> destination, through ipsec0. One solution would involve re-thinking
Sam> this
Sam> logic.
Sure. We can do that. I don't see any value. ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON |net architect[ ] mcr(at)sandelman.ottawa.on.ca http://www.sandelman.ottawa.on.ca/ |device driver[ ] panic("Just another Debian GNU/Linux using, kernel hacking, security guy"); [-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.7 (GNU/Linux) Comment: Finger me for keys
iQCVAwUBPnADJoqHRg3pndX9AQG07AP/Vbdutk3kyjEL9QF4oGZT3W+rWeK/aW/C
ILvblht2IeSapGNBpDl892GzTHoN6K5VumMMJQ5Uh8ye3yoax0gdzOBdS6t+dXAk
lUa5CVKRamvtCMsxIZZZ+SpWjo4L8MCXFHv/fUz3+kN4J5DD2Fz6/f6ghmUPcXrY
fOJI6fkspPs=
Design mailing list Design@lists.freeswan.org http://lists.freeswan.org/mailman/listinfo/design Received on Thu Mar 13 02:35:25 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 12:59:57 EDT |
||||||||||
|
|||||||||||