|
|||||||||||
|
Re: [Design] IPSec in 2.5 Kernel?
From: John S. Denker <jsd(at)monmouth.com>
Date: Thu Mar 20 2003 - 04:15:07 EST
On 03/20/2003 02:39 AM, Derek Atkins wrote:
Yes, that's what I mean when I speak of a subnet-to-subnets
VPN.
Yes, that's what I mean when I speak of dynamic addresses. > If "automatic keying" means "IKE with RSA without
Yes, when I speak of automatic keying I mean IKE as opposed to manual keying. I forgot to mention RSA but yes, that's what I had in mind. > then yes, it can do that (although only
I'm delighted to hear it. But tell me, how does my security policy get set up when my peers have non-static addresses? I know about racoon's generate_policy option as mentioned in e.g. http://www.qnx.com/developer/docs/momentics_nc_docs/neutrino/utilities/r/racoon.conf.html but my little brain doesn't see a convenient way to make it secure. Suppose a peer that's supposed to have access to one of my subnets wants access to another of (or all of) my subnets. How do I prevent this? Design mailing list Design@lists.freeswan.org http://lists.freeswan.org/mailman/listinfo/design Received on Thu Mar 20 04:49:05 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 12:59:57 EDT |
||||||||||
|
|||||||||||