Re: how to configure a FreeBSD firewall to pass IPSec?

From: Fernando Gleiser (fgleiser_at_cactus.fi.uba.ar)
Date: 05/02/03

  • Next message: mario: "Did i get hacked?"
    Date: Fri, 2 May 2003 16:06:50 -0300 (ART)
    To: Guy Middleton <guy@obstruction.com>
    
    

    On Wed, 30 Apr 2003, Guy Middleton wrote:

    >
    > Ok, now I'm confused. The same client (Cisco VPN 3.5 on Windows) works
    > through a LinkSys router / NAT gateway (a BEFSR81) at a different location.
    > The LinkSys even has a friendly little check-box to allow IPSec pass-through.
    >
    > I would like the FreeBSD gateway to work the same way as the LinkSys.

    I have set up both Cisco and Checkpoint VPNs behind a FreeBSD router/firewall
    runing IPFilter using both ESP and UDP encapsulation. It works like a charm.
    In the ESP case, I have to 'bimap' (one to one NAT) the internal host
    to an external IP. The UDP encapsulated case worked right out of the box.

                            Fer

    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


  • Next message: mario: "Did i get hacked?"