Re: (slightly OT) IPSec with dynamic IP

From: Fernando Gleiser (
Date: 12/10/02

Date: Mon, 9 Dec 2002 23:40:04 -0300 (ART)
From: Fernando Gleiser <>
To: Eric Anderson <>

On Mon, 9 Dec 2002, Eric Anderson wrote:

> 1. Yes, it is possible.. You'll have to do something with certificates
> probably, or use mpd on the server end. There are other solutions,
> those are just a few things..

It *has* to be IPSec (corporate policy), so mpd as PPTP server is out of
the question.

> 2. Maybe.. Are you trying to connect each individual windows box, or
> are you going to have a firewall/gateway that does this for all of them
> (the entire lan)?

I want each of the remote Windows boxes to see the corporate LAN. We have
a FreeBSD box as firewall, which will be the local node of the tunnel.

> 3. I don't know .. maybe... I have this working, so maybe I should
> write one up.. :)

Well, if you have some config files I can use as an example (with the names
and IP changed to protect the innocent, of course), I'd be very grateful.

> Eric
> --
> ------------------------------------------------------------------
> Eric Anderson Systems Administrator Centaur Technology
> Beware the fury of a patient man.
> ------------------------------------------------------------------

To Unsubscribe: send mail to
with "unsubscribe freebsd-security" in the body of the message