Re: Transport Mode IPSEC



On Wed, 17 Jan 2007, Ted Mittelstaedt wrote:

Dan,

You do realize, don't you, that since both of these hosts are on a switch,
and are using unicast traffic to communicate with each other, that they
cannot be sniffed, don't you?

That implies trust of the switch, trust against arp-cache poisoning, and the like. The idea of ipsec is not trusting the wire.

With NIS/NFS known for being this inherently secure, would it get me a better answer if I said "with only a single router between them"?

-Dan


--


--------Dan Mahoney--------
Techie, Sysadmin, WebGeek
Gushi on efnet/undernet IRC
ICQ: 13735144 AIM: LarpGM
Site: http://www.gushi.org
---------------------------

_______________________________________________
freebsd-questions@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: Transport Mode IPSEC
    ... On 1/18/07, Ted Mittelstaedt wrote: ... You do realize, don't you, that since both of these hosts are on a switch, ... You might read up on ethernet switching technology a bit before ...
    (freebsd-questions)
  • Strange results from a tcpdump, can anyone help?
    ... traffic was going ballistic on most ports in the network. ... other hosts went to normal (i.e. the only traffic you could see were ... packets from the same vlan destined to other hosts outside ... If it was simply a bad switch with a bad port that had lost it's mac ...
    (comp.dcom.lans.ethernet)
  • Re: Strange results from a tcpdump, can anyone help?
    ... traffic was going ballistic on most ports in the network. ... other hosts went to normal (i.e. the only traffic you could see were ... packets from the same vlan destined to other hosts outside ... If it was simply a bad switch with a bad port that had lost it's mac ...
    (comp.dcom.lans.ethernet)
  • Re: Broadcast Packets Evil?
    ... hosts on a switch, the bandwidth of the switch should sustain the connection, ... and they'll just be a momentary spike in network traffic. ... 200 cables with 199 hosts on each, ...
    (comp.os.linux.networking)
  • RE: A problem with a function Microsoft Update - an error
    ... switch off the sw firewalls, ... checked the file Hosts if there isn't any static IP address, ... cancel all additional toolbars from my IE 7.0, ...
    (microsoft.public.windowsupdate)