Re: VPN on 2.4.x kernels

From: A transfinite number of monkeys (jcostom@jasons.org)
Date: 01/23/02


From: jcostom@jasons.org (A transfinite number of monkeys)
Date: Wed, 23 Jan 2002 15:48:03 GMT

In article <slrna4qdqj.oj.blancher@elendil.intranet.cartel-info.fr>,
        Cedric Blancher wrote:
: IPSEC filtering : IP protocol 50 (ESP)
: IP protocol 51 (AH)
: UDP source port 500, destination port 500 (ISAKMP)
:
: IPSEC does not like NAT : it only works in tunnel mode, without AH.
: Moreover, you need to play with SPI in ordre to established more than
: one tunnel for your network to the same peer.

OR implement some sort of encapsulation protocol for the ESP traffic.
Many IPSec clients do this: Nokia (IPSec over NAT Working Draft), Check
Point (own proprietary UDP-based encapsulation), Nortel (GRE, IIRC - blech!),
etc.

AH seems just silly, if you ask me. You need that functionality?
Ok, run ESP with null encryption. You get the same benefits AND can
get shot through NAT devices.

-- 
Jason Costomiris <><           |  Technologist, geek, human.
jcostom {at} jasons {dot} org  |  http://www.jasons.org/ 
          Quidquid latine dictum sit, altum viditur.
                    My account, My opinions.



Relevant Pages

  • Re: VPN From W2K/Pro to W2K Server Doesn;t Work Through Firewall
    ... My belief is that your NAT ... My understanding is that IPSec AH protocol does not work with NAT devices ... IPSec operates in either one of two modes - transport mode or tunnel mode. ... provide a VPN remote access solution. ...
    (microsoft.public.win2000.security)
  • Re: VPN From W2K/Pro to W2K Server Doesn;t Work Through Firewall
    ... something like "windows-2000 AH ESP VPN NAT" ... My belief is that your NAT ... > My understanding is that IPSec AH protocol does not work with NAT devices ... > IPSec operates in either one of two modes - transport mode or tunnel mode. ...
    (microsoft.public.win2000.security)
  • Re: Front End/Back End communication
    ... IPSec has two modes--tunnel and transport. ... "The tunnel mode is used in cases when security is ... it should work with NAT. ... ESP in transport mode is incompatible with NAT of PAT ...
    (Focus-Microsoft)
  • Re: L2TP/IPSec Verbindung läuft mit XP SP2 nicht mehr
    ... In XPSP2 the IPsec driver needs a registry setting when either the ... server or workstation are behind a NAT gateway. ... 1- Client initiates to a server that is behind the NAT ... > Peer Private Addr ...
    (microsoft.public.de.german.windowsxp.networking)
  • Re: IPsec + NAT + mehrere Tunnelendpunkte
    ... Ist der VPN-Endpunkt ein Cisco Concentrator oder eine PIX? ... Und warum macht er dort ueberhaupt doppelt NAT? ... Session-Keys des IPSEC Tunnels verwendet. ...
    (de.comp.security.firewall)