New Zealand ADSL Mailing List


RE: More pinholes!

From: Steve <steve_at_focb.iconz.co.nz>
Date: Tue, 25 Jan 2000 19:48:40 +1300 (NZDT)
Message-ID: <Pine.LNX.4.10.10001251942370.2085-100000@gateway.focb.iconz.co.nz>

or you could setup a GRE tunnel useing IP protocol 47 then run ip protocol
tunneled over this, i know its a nasty solution but if it works - hey, why
not ?

one thing i have noticed tho with useing tunneling is that the ping times
increase by a few milliseconds, if i ping the DSL box directly i get in
the reion of 35ms replies, via the tunnel i am getting around 40ms
replies, not really too much of a problem tho but you'll prolly find it
gets worse the more you encapsulate stuff..

if anyone wants to know how to setup a GRE or pptp (linux has a pptp
server/client that works with M$ products if anyones interested) via the
m10 then feel free to drop me an e-mail or mail the list.

note : your ISP will probably need to support it - i would say paradise
wouldnt have a problem, and i'm sure jeremy would be willing to give it a
try - good luck for you xtra people :) and if you ring me at iconz then we
can see what we can do. Another thing to note - tunneling could turn out
to be expensive, so expect your isp to charge for the setup time, ip
allocation and equipment involved in doing this :)

--
Steve.
On Tue, 25 Jan 2000, Oliver Mannion wrote:
> I know of no way. I would suggest either an internal card,
> or obtaining a modem/router other than the m10 that supports
> PPPoe - approach Telecom see if they will let you do this.
> 
> At 14:39 25/01/00 +1300, you wrote:
> >SSH has certainly some good applications, but in this case I'm looking at
> >using the Firewall vendor's remote VPN client with strong encryption to
> >tunnel through a bunch of protocols - not just telnet.
> >
> >> -----Original Message-----
> >> From: Jeremy Elgin [mailto:nz-adsl@lists.cafe.co.nz]
> >> Sent: Tuesday, 25 January 2000 1:50
> >> To: Edkins, Rob - Axon AKL; adsl@freebsddiary.cx
> >> Subject: Re: More pinholes!
> >> 
> >> 
> >> Have you considered SSH? It tunnels over TCP.
> >> 
> >> > In their travels has anyone come across a way of extending the range
> >> of IP
> >> > packet types that can be pinholed on the M10?
> >> > I'm trying to set up an IPSec encrypted tunnel for 
> >> teleworking, and I
> >> need
> >> > to pass IP type 50 (ESP) and 51 (AH) packets.
> >> > Currently, the only options are TCP, UDP, ICMP and PPTP (GRE).
> >> > I'll use PPTP if I have to, but it would be nice to use something
> >> stronger.
> >> 
> >> 
> >> 
> >> To unsubscribe: send mail to majordomo@freebsddiary.cx
> >> with "unsubscribe adsl" in the body of the message
> >> 
> >
> >To unsubscribe: send mail to majordomo@freebsddiary.cx
> >with "unsubscribe adsl" in the body of the message
> >
> >
> >
> >
> 
> To unsubscribe: send mail to majordomo@freebsddiary.cx
> with "unsubscribe adsl" in the body of the message
> 
To unsubscribe: send mail to majordomo@freebsddiary.cx
with "unsubscribe adsl" in the body of the message
Received on Tue Jan 25 19:44:22 2000

This archive was generated by hypermail 2.2.0 : Thu Nov 30 11:48:03 2006 EST