From owner-freebsd-security Thu Jan 24 11: 6:41 2002 Delivered-To: freebsd-security@freebsd.org Received: from proxy.centtech.com (moat.centtech.com [206.196.95.10]) by hub.freebsd.org (Postfix) with ESMTP id 9362E37B404 for ; Thu, 24 Jan 2002 11:06:24 -0800 (PST) Received: from sprint.centtech.com (sprint.centtech.com [10.177.173.31]) by proxy.centtech.com (8.11.6/8.11.6) with ESMTP id g0OJ6NK28560; Thu, 24 Jan 2002 13:06:23 -0600 (CST) Received: from centtech.com (proton [10.177.173.77]) by sprint.centtech.com (8.9.3+Sun/8.9.3) with ESMTP id NAA20377; Thu, 24 Jan 2002 13:06:22 -0600 (CST) Message-ID: <3C505AFD.52FF9ADE@centtech.com> Date: Thu, 24 Jan 2002 13:05:33 -0600 From: Eric Anderson Reply-To: anderson@centtech.com Organization: Centaur Technology X-Mailer: Mozilla 4.78 [en] (X11; U; Linux 2.2.12 i386) X-Accept-Language: en MIME-Version: 1.0 To: dr3node Cc: freebsd-security@freebsd.org Subject: Re: Can't set up an IPsec tunnel. References: <200201241847.AHX10883@vmms1.verisignmail.com> <3C50588C.7200324B@centtech.com> <200201241900.AHX11812@vmms1.verisignmail.com> Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org As far as I know, no, because that would be like a "man in the middle" attack (I think). Like this: A <--- B ---> C If A is talking to C via IPSEC, A tells C it's IP (the true IP) and C tells A it's IP (its true IP, behind the masquaraded host), but A sees C as B's IP address. How does it know that C knows that B exists? Maybe there is a way to forward or tunnel certain protocols through the Linux box, but this doesn't sound like a good idea to me. You could always use the old crusty SSH tunneling VPN's.. :) Eric P.S. - Don't ask how to do it with SSH. It's been too long. dr3node wrote: > > On Thursday 24 January 2002 21:55, you wrote: > > IPSEC won't work through masquarading boxes or NAT firewalls. > > > > Eric > > is there any way way to cheat? > > To Unsubscribe: send mail to majordomo@FreeBSD.org > with "unsubscribe freebsd-security" in the body of the message -- ------------------------------------------------------------------ Eric Anderson anderson@centtech.com Centaur Technology If at first you don't succeed, sky diving is probably not for you. ------------------------------------------------------------------ To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message