New Zealand ADSL Mailing List


Re: M10s & Checkpoint VPNs

From: Don Stokes <don_at_daedalus.co.nz>
Date: Thu, 08 Jun 2000 09:55:09 +1200
Message-Id: <200006072155.JAA17215@gw.zl2tnm.gen.nz>

rob.edkins@axon.co.nz wrote:
>> Well, I'm happily sitting behind an M10 talking over Securemote now
>> too. And y'know what? I *didn't* need a pinhole.
>>
>Hi Don, are you using IKE with ESP or AH?

IKE w/ ESP. AH includes the IP addresses in the checksum (computed
before encryption) so any kind of NAT irreversibly breaks AH. ESP
is fine.

-- don

This message is part of the NZ Broadband mailing list.
see http://freebsddiary.cx/adsl/ for archives, FAQ,
and various documents.
To unsubscribe: send mail to majordomo@freebsddiary.cx
with "unsubscribe adsl" in the body of the message
Received on Thu Jun 8 09:56:08 2000


This archive was generated by hypermail 2.2.0 : Thu Nov 30 11:48:04 2006 EST