|
|||||||||||
|
Re: [Users] ... only secure communication
From: John S. Denker <jsd(at)monmouth.com>
Date: Thu Mar 27 2003 - 14:53:41 EST
On 03/27/2003 09:32 AM, Pavel Chvalkovský wrote:
Definitely it can. I've been doing this for years. > when it doesn't support this security feature?
Please refer to http://www.monmouth.com/~jsd/vpn/ipsec+routing/cns.htm In particular the part where it says:
Some people say FreeS/WAN "doesn't support" inbound
policy checking. Well, maybe, but remember that
supported/unsupported does not mean the same thing as
mandatory/recommended/deprecated/forbidden.
FreeS/WAN does not "support" awk, but it is mandatory.
You must provide awk on your own, or FreeS/WAN won't run.
Similarly, FreeS/WAN won't do your inbound policy
checking or other unbadness checks, but it is strongly
recommended that you do it on your own. You can do this
using the plain old packet-filtering mechanism. Writing the
code to do this is laborious and slightly tricky. You need a
first loop over all devices allowing good things to happen,
and then you need a second loop over all devices
disallowing everything else. You can't do it using just one
loop (except in the simplest cases).
You could, but you would almost certainly be better off using RSA. Users mailing list Users@lists.freeswan.org http://lists.freeswan.org/mailman/listinfo/users Received on Thu Mar 27 20:02:03 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 13:01:11 EDT |
||||||||||
|
|||||||||||