|
|||||||||||
|
[Users] Re: [Design] how FS is supposed to deal with problems further down the stack
From: Nico Baggus <mlfreeswan(at)noci.xs4all.nl>
Date: Tue Mar 11 2003 - 19:27:05 EST
Appearantly they didn't make it to the list, (or back to until now)
So here it is again ,
kind regards,
On Monday 10 March 2003 14:12, martin f krafft wrote:
If redesigning please keep the following into mind.... (internet) ----- DSLAM -- ADSL/MDM <1.1.1.1> --- <Internet Address> FS Host - Localnet (192.168.x.x) This can be setup with routes like : On the adsl modem: a host route to <internet address> through interface with 1.1.1.1 On FS-Host: (assuming the FS host internet interface is eth0)
add route 1.1.1.1/32 dev eth0
ALL the ipsec routes should then be added with
route add -net <net>/<mask> dev ipsec0
Also the net/net vs. net/host vs host/host can be solved at the routing layer
by specifying that for leaving packets a different interface address should be
used
kind regards,
Users mailing list Users@lists.freeswan.org http://lists.freeswan.org/mailman/listinfo/users Received on Tue Mar 11 23:37:32 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 13:00:46 EDT |
||||||||||
|
|||||||||||