|
|||||||||||
|
Re: [Users] both ends dynamic and using dns names rather than ip
From: Brian J. Murrell <brian(at)interlinx.bc.ca>
Date: Thu Oct 09 2003 - 22:13:23 EDT On Thu, 2003-10-09 at 13:25, Erich Titl wrote:
Hi Erich, > OK, I believe this is pretty standard.
Right. But this still has the problem that if the connection drops on one end or the other, the end that dropped the connection cannot always be the initiator of the tunnels because the other end was configured using the IP that the FQDN resolved to when it was started (i.e. prior to the other end having been given a new address). To re-iterate previous messages in this discussion, ideally, pluto does not care what IP address a connection/session request comes from as long as it has an RSA key, and on the sending end, pluto resolves the FQDN specified in the config file every time it re-sends (i,e, previous attempts time out) connection/session setup requests. [ realizing that this is probably not really fodder for the "users" list...] Are there any technical barriers (i.e. major design issues) to implementing this or is it just a case of something that just has not been done yet? b. -- My other computer is your Microsoft Windows server. Brian J. Murrell
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 13:02:04 EDT |
||||||||||
|
|||||||||||