RE: Gif IPTunnel networkA-to-networkB not work

From: Oldach, Helge (Helge.Oldach_at_atosorigin.com)
Date: 08/27/03

  • Next message: Christoffer Pio: "subnetting C class into /26 /25 /26, why can this be done?"
    To: hilman firmansyah <hilman@nap.net.id>, freebsd-net@freebsd.org
    Date: Wed, 27 Aug 2003 08:40:27 +0200
    
    

    > From: hilman firmansyah [mailto:hilman@nap.net.id]
    > NB : I still dont touch the IPSEC and encrypted section
    > ,since in the fbsd
    > handbooks said to make an encrypted section i must have the 2 networks
    > connected. Is this right?

    You must have the networks connected (on the public side), but when using
    IPSec your gif tunnel won't really be used. It is just sort of a
    "placeholder"
    to get the routing correct. I am using a similar setup to your's (FreeBSD
    talking IPSec with a Cisco router) using the GIF tunnel pointing to a bogus
    remote address. You could essentialy achieve the same without GIF using
    static ARP entries, claiming that the MAC address of your machine's default
    gateway has the tunnel destination IP.

    Helge
    _______________________________________________
    freebsd-net@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-net
    To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org"


  • Next message: Christoffer Pio: "subnetting C class into /26 /25 /26, why can this be done?"

    Relevant Pages

    • Re: IPSEC with PF - Please help.
      ... In terms of PF firewall work with IPSEC, do I still need to enable ... Anything that you route through the GIF tunnel, ... Mike Tancsa, Sentex communications http://www.sentex.net ... Providing Internet Access since 1994 ...
      (comp.unix.bsd.freebsd.misc)
    • Re: DF (Dont frag) issues
      ... > setup with the gif tunnel (but no IPSec) and it works just fine for me. ... ipf/ipfw/pf and VPNs - to date I have used iptables and ...
      (freebsd-current)
    • RE: Gif IPTunnel networkA-to-networkB not work
      ... > To: Oldach, Helge ... >> using IPSec your gif tunnel won't really be used. ... to set up a gif tunnel in order to set up a IPSec tunnel. ...
      (freebsd-net)
    • more on IPSec + gif stalling
      ... I've done another test on the IPSec + gif issue. ... Set up IPSec rules for both machines, created a gif tunnel between both ... IPSec + gif - firewall = just works ...
      (freebsd-net)
    • RE: Quick Routing Question
      ... The wireless router didn't ... > Now it's time to get IPSEC set up. ... You have any q's in your new venture that aren't related to FBSD ... I'd say, if you have an extra nic, add a new 172.16/16 subnet in the ...
      (freebsd-questions)