|
|||||||||||
|
Re: [Design] IPSec in 2.5 Kernel?
From: Derek Atkins <derek(at)ihtfp.com>
Date: Thu Mar 20 2003 - 18:46:41 EST John, "John S. Denker" <jsd@monmouth.com> writes: > > then yes, it can do that (although only
I _believe_ that you can configure multiple "remote anonymous" sections, each with their own identities. I have never actually tested it, so it may not work right. It does appear that you must share the "sainfo" across all "anonymous" connections.... > http://www.qnx.com/developer/docs/momentics_nc_docs/neutrino/utilities/r/racoon.conf.html
I _believe_ you can just set the SPD to define what access is allowed. So for example you can say that 10.0.0.0/28 can only access 192.168.1.0/28, and 10.0.0.32/28 can only access 192.168.1.32/28.... I do need to take a closer look at road-warrior configurations to make sure they work. I have not had the chance to play with that yet, but I'll make sure to do so after I finish NAT-T. -derek
--
Derek Atkins
Computer and Internet Security Consultant
derek@ihtfp.com www.ihtfp.com
_______________________________________________
Design mailing list
Design@lists.freeswan.org
http://lists.freeswan.org/mailman/listinfo/design
Received on Thu Mar 20 19:43:38 2003This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 12:59:57 EDT |
||||||||||
|
|||||||||||