Re: IPSec tunnel interfaces (was: freebsd vpn server behind nat dsl router)



Hi Yvan,

On Wed, Mar 07, 2007 at 06:06:17PM +0100, VANHULLEBUS Yvan wrote:
- FreeBSD handbook talks about Gif interfaces for IPSec tunnels. Just
forget that part and use directly IPSec tunnels without Gif
interfaces.

While I understand why using gif(4) to create IPSec tunnels is
not recommended because of interoperability, administratively it
is pretty useful to see the tunnel as an interface. Everything
that comes along such as routes, firewall rules et al work very
naturally. I'm no IPSec expert as you probably are and I seem
to recall the RFC advises (requires ?) it to be implemented as a
bump in a stack. However, is it reasonable to expect to see
this in the future ?

It seems the enc(4) interface provides this feature somehow but
only for FAST_IPSEC. What is the doom of IPSEC ? Are they to
be merged in the future, or is it possible to make the enc(4)
work with IPSEC as well ?

Thank you.
Regards,
--
Jeremie Le Hen
< jeremie at le-hen dot org >< ttz at chchile dot org >
_______________________________________________
freebsd-security@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: IPSec Interfaces
    ... What do you expect IPSec to give you? ... Network Interface. ... Does the interface show up under Network Connections? ... Perhaps the driver for the modem needs to be updated. ...
    (microsoft.public.windowsxp.security_admin)
  • ipsec problem
    ... I have one firewall that also does ipsec. ... I installed a client machine, still Sarge with same software, that should ... when I connect from the client to the one server inside the LAN, ... pluto: adding interface ppp0/ppp0 XX.XX.XX.XX ...
    (Debian-User)
  • Re: (long) Re: Using racoon-negotiated IPSec with ipfw and natd
    ... IPsec processing of the outgoing packet happens ... >> external interface. ... > allowing the traffic before the natd divert. ... saying on which interface the ipfwrules pass packets to natd. ...
    (FreeBSD-Security)
  • Re: (long) Re: Using racoon-negotiated IPSec with ipfw and natd
    ... IPsec processing of the outgoing packet happens ... >> external interface. ... > allowing the traffic before the natd divert. ... saying on which interface the ipfwrules pass packets to natd. ...
    (freebsd-net)
  • Re: asp.net
    ... Snap-in selection in the drop menu, ... pop-up messages from network sense telling you that the ... >>One normally sees the IPsec message that you mention ... >>when one network capable interface has not finished its ...
    (microsoft.public.windowsxp.security_admin)