Re: ipsec (was RE: nokia m10 # of pinholes)
From: Nicholas Lee <nj.lee-web_at_kiwa.co.nz>
Date: Thu, 4 May 2000 17:38:35 +1200 Message-ID: <003c01bfb58a$fe1708e0$0408a8c0@kiwa.co.nz>
> there has been some (off list aiui) suggestion that
This is a fundamental problem between IPSec and NAT. In theory you should
I think my fundamental problem was getting the IPSec to accept the packets
[ESP only hashes the payload, not the headers.]
With the current setup is to get a GRE tunnel, and do IPSec over that. I
Personally I've almost managed to get it to work with two openbsd boxes and
Telecom are trialling a M10 to M10 VPN solution at the moment.
> of course since we have deployed a genuine (no flames
Join a lot of us.
> but telecom won't allow us to run the m10 in bridge
Have you read the archives. There was a discussion of this a while back.
> i wonder if we could avoid this difficulty if we swapped
No drivers for a secure robust network OS. 8( I've heard that other DSL
The other (non) option is routing a public subneting. Unfortunately Telecom
Currently I've given up on GRE or IPSec and I'm just running vtun
It's definitely work worth considering putting some community pressure on
Nicholas
To unsubscribe: send mail to majordomo@freebsddiary.cx
|
This archive was generated by hypermail 2.2.0 : Thu Nov 30 11:48:04 2006 EST