Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

[Users] Re: [Design] mast(4)

From: John S. Denker <jsd(at)monmouth.com>
Date: Fri Mar 14 2003 - 14:11:42 EST

On Fri, 14 Mar 2003, I wrote:

 >http://www.monmouth.com/~jsd/vpn/ipsec+routing/mast.htm#sec-transport-pvt

On 03/14/2003 01:57 PM, Jim Carter wrote:

> Interesting discussion. When eventually implemented, this looks like
> the solution to my problem of a road warrior behind a closed source
> NAT box (residential or hotel gateway), where different hotels give
> different peers the same "wild-side" address such as 192.168.0.1.

I doubt that's the solution to this problem. Your base station will never utter any such address. Your base station will utter the address of the hotel's NAT box.

> However, I'm wondering if transport mode (vs. tunnel mode) will
> support packets intended to leave the secure gateway

What means secure gateway? The only gateway I see mentioned so far is the hotel NAT box, which doesn't contribute anything to IPsec security.

Do you need help?X

> -- I got the impression that it wouldn't. In the paradigm case, the
> road warrior's default route is down the tunnel/transport, and the
> gateway routes his packets to the global internet (doing NAT on the
> way out), and it then sends reverse-NATted returning packets down the
> correct tunnel despite the non-unique IP addresses on the various
> hotels' internal nets.

Isn't this just the usual IPsec NAT-traversal situation?

> I think the "just" clause got corrupted.

Fixed now. Thanks.

  • jsd

Users mailing list
Users@lists.freeswan.org
http://lists.freeswan.org/mailman/listinfo/users Received on Fri Mar 14 17:19:11 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 13:00:50 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library