Re: IPSEC in tunnel mode ( possible? )

From: Crist J. Clark (cristjc_at_comcast.net)
Date: 10/31/03

  • Next message: David Carter-Hitchin: "ppp link always dials when started with -auto?"
    Date: Thu, 30 Oct 2003 15:30:18 -0800
    To: Nucleo de Pesquisa e Desenvolvimento <npd@el.com.br>
    
    

    On Wed, Oct 29, 2003 at 06:15:40PM -0200, Nucleo de Pesquisa e Desenvolvimento wrote:
    > Hi everyone,
    >
    > I know it is kind an off-topic question but maybe another network admin
    > have already faced the following:
    >
    > client--[__ipsec__]--gw--[__ip__]--internet
    >
    > I, trying to secure a wireless link, want to have my clients using
    > ipsec on the segment between the gateway gw and the machine itself even
    > when the traffic is to the internet and not only to the gateway ( what
    > works fine in transport mode anyway ). The clients are windows
    > machines.
    > Accordingly to Microsoft 252735 tunnel is possible when a windows is
    > acting as a gateway, not our scenario where machines are only
    > clients...

    Sometimes you read something and you just wanna pound someone so, so
    hard with a clue bat,

      "Windows 2000 IPSec tunneling is not supported for client remote
       access VPN use because the IETF IPSec RFCs do not currently provide
       a remote access solution in the Internet Key Exchange (IKE) protocol
       for client-to-gateway connections."

    First, IPsec is a peer-to-peer protocol. There are no clients and
    servers, only peers. Second, IKE is not part of IPsec. IKE is a nice
    standard for setting up IPsec SAs, but it is not required and is not
    the only way to set up SAs. Third, there are plenty of ways to do
    IKE authentication in a "cleint-to-server-like" fashion. A zillion
    other vendors have somehow managed to figure this out, M$.

    > Any one could point me to some url or send me keywords I should look
    > for please? If things won?t work with ipsec I?ll do it with MPD... but
    > I still should have ask it here.

    FWIW, I ended up using mpd for Windows machines this exact same
    scenario.

    -- 
    Crist J. Clark                     |     cjclark@alum.mit.edu
                                       |     cjclark@jhu.edu
    http://people.freebsd.org/~cjc/    |     cjc@freebsd.org
    _______________________________________________
    freebsd-net@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-net
    To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org"
    

  • Next message: David Carter-Hitchin: "ppp link always dials when started with -auto?"

    Relevant Pages

    • IPSec+VPN+ipfw questions
      ... I wish to use IPSec to provide secure channels between some LAN machines ... and a FreeBSD gateway which acts as a NAT router to the ... there are some strange situations with Windows 2000 machines which are ...
      (freebsd-questions)
    • Re: How to encrypt all network traffic
      ... I don't want to tunnel. ... I want to encrypt IP between two machines. ... there any IPSec clients out there that make this easy? ... Windows 2000 IPSec policies, the problem is the end user. ...
      (Security-Basics)
    • Re: Should I install Certificate Authority to solve these problems ?
      ... You can use IPsec with or without certs from your PKI. ... negotiations to your AD machines or those trusting the ... > In the item 1 below, the tool in use is a HP server management tool (type ... >>> Management is pushing to get Certificate Authority ...
      (microsoft.public.win2000.security)
    • Cisco PIX remote VPN mit neuer IP
      ... Die Cisco PIX wurde soweit angepasst das der Zugriff ins Internet aus dem LAN wieder funktioniert. ... Microsoft IPSec Policy Agent service stopped successfully ... Received IOS Vendor ID with unknown capabilities flag 0x000000A5 ... Crypto Active IKE SA, 0 User Authenticated IKE SA in the system ...
      (de.comp.security.firewall)
    • Re: can xp act as server for vpn connection
      ... IPSEC L2TP connections won't work behind a NAT firewall without ... included in Windows XP... ... >>you can set the security policy on the client connection. ...
      (microsoft.public.windowsxp.work_remotely)