Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: [Design] IPSec in 2.5 Kernel?

From: John S. Denker <jsd(at)monmouth.com>
Date: Thu Mar 20 2003 - 04:15:07 EST

On 03/20/2003 02:39 AM, Derek Atkins wrote:
>
> I _presume_ what you mean is that you've got a VPN gateway at

Yes, that's what I mean when I speak of a subnet-to-subnets VPN.
> I also presume that the satellite

Yes, that's what I mean when I speak of dynamic addresses.

> If "automatic keying" means "IKE with RSA without

Yes, when I speak of automatic keying I mean IKE as opposed to manual keying. I forgot to mention RSA but yes, that's what I had in mind.

> then yes, it can do that (although only

I'm delighted to hear it.

Do you need help?X

But tell me, how does my security policy get set up when my peers have non-static addresses? I know about racoon's generate_policy option as mentioned in e.g.

http://www.qnx.com/developer/docs/momentics_nc_docs/neutrino/utilities/r/racoon.conf.html

but my little brain doesn't see a convenient way to make it secure. Suppose a peer that's supposed to have access to one of my subnets wants access to another of (or all of) my subnets. How do I prevent this?



Design mailing list
Design@lists.freeswan.org
http://lists.freeswan.org/mailman/listinfo/design Received on Thu Mar 20 04:49:05 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 12:59:57 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library