Re: gif(4) & ipsec [was: ICMP_UNREACH_NEEDFRAG broken in -current]

From: Bjoern A. Zeeb (bzeeb-lists_at_lists.zabbadoz.net)
Date: 09/27/04

  • Next message: Juhani Tali: "Nat problem, nat and proxy_address at the same time."
    Date: Mon, 27 Sep 2004 11:39:40 +0000 (UTC)
    To: Brian Somers <brian@Awfulhak.org>
    
    

    On Mon, 27 Sep 2004, Brian Somers wrote:

    > On Mon, 27 Sep 2004 10:59:54 +0000 (UTC), "Bjoern A. Zeeb" <bzeeb-lists@lists.zabbadoz.net> wrote:
    > > On Mon, 27 Sep 2004, Brian Somers wrote:
    > >
    > > > The outside network segment is an IPSEC configuration with gif interfaces
    > > ...
    > > > Comments/suggestions/flames?
    > >
    > > most likely unrelated but I need input on this so ...
    > > why do you need gif(4) ?
    >
    > With an ipsec-only solution, talking from a gateway box to an internal
    > host on the ``other'' network doesn't work nicely....

    ok.

    > especially if the internal host on the other network doesn't have a
    > route for it.

    considering the usage of a vpn-gw/router most services needed like
    ssh, ping and possibly telnet can be given a source address on command
    line to use the internal IP. anyway it's complicating things, you are
    right.

    thanks for the detailed explanation.

    -- 
    Bjoern A. Zeeb				bzeeb at Zabbadoz dot NeT
    _______________________________________________
    freebsd-net@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-net
    To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org"
    

  • Next message: Juhani Tali: "Nat problem, nat and proxy_address at the same time."

    Relevant Pages

    • Re: VPN and remote gateway
      ... > It seems you use the wrong route add command. ... > when the VPN connection is established. ... > | using the remote network as my gateway. ...
      (microsoft.public.windows.server.sbs)
    • Re: Persistent Route ignored on W2K when destination network is unavailable
      ... a global setting like the gateway to a particular subnet should be set ... this network access the internet via a NAT firewall (connected to ... via a WAN link. ... route on the Cisco firewall so that any traffic to the internet gets ...
      (microsoft.public.win2000.networking)
    • Re: AIX 1.3 Failures and Fables
      ... DESTINATION GATEWAY FLGS REFCNT USE INTERFACE ... Is my interpretation of the AIX 1.3 #man route correct? ... Manually manipulates the routing tables. ... Is the destination host or network. ...
      (comp.sys.ibm.ps2.hardware)
    • Re: AD-DNS-DHCP
      ... If I do NOT remove the gateway configurationfrom my DHCP ... scope but add route command to my logon script, ...
      (microsoft.public.windows.server.active_directory)
    • Re: AD-DNS-DHCP
      ... Ipconfig will show a second default gateway. ... You could set a metric for the additional gateway, or you could run Route Delete 0.0.0.0 first, ... "Jorge Silva" wrote in message ... If I do NOT remove the gateway configurationfrom my DHCP scope but add route command to my logon script, which one will ultimately prevail, the DHCP gateway configuration or the route add command in the logon script? ...
      (microsoft.public.windows.server.active_directory)