Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: [Design] IPSec in 2.5 Kernel?

From: Derek Atkins <derek(at)ihtfp.com>
Date: Thu Mar 20 2003 - 18:46:41 EST

John,

"John S. Denker" <jsd@monmouth.com> writes:

> > then yes, it can do that (although only

I _believe_ that you can configure multiple "remote anonymous" sections, each with their own identities. I have never actually tested it, so it may not work right. It does appear that you must share the "sainfo" across all "anonymous" connections....

> http://www.qnx.com/developer/docs/momentics_nc_docs/neutrino/utilities/r/racoon.conf.html

I _believe_ you can just set the SPD to define what access is allowed. So for example you can say that 10.0.0.0/28 can only access 192.168.1.0/28, and 10.0.0.32/28 can only access 192.168.1.32/28....

I do need to take a closer look at road-warrior configurations to make sure they work. I have not had the chance to play with that yet, but I'll make sure to do so after I finish NAT-T.

Do you need help?X

-derek

-- 
       Derek Atkins
       Computer and Internet Security Consultant
       derek@ihtfp.com             www.ihtfp.com
_______________________________________________
Design mailing list
Design@lists.freeswan.org
http://lists.freeswan.org/mailman/listinfo/design
Received on Thu Mar 20 19:43:38 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 12:59:57 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library