Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 19 Mar 2013 07:56:50 +0100
From:      Yoann Gini <yoann.gini@gmail.com>
To:        Eugene M. Zheganin <emz@norma.perm.ru>
Cc:        freebsd-net@freebsd.org
Subject:   Re: mpd5 and multiple route to send to clients
Message-ID:  <1306548A-C393-44DF-9B8D-9A34D806622E@gmail.com>
In-Reply-To: <5147EE5D.5070203@norma.perm.ru>
References:  <9EC8E2D3-A52B-4FF1-B840-3D962DF8D917@gmail.com> <5147EE5D.5070203@norma.perm.ru>

next in thread | previous in thread | raw e-mail | index | archive | help

[-- Attachment #1 --]

Le 19 mars 2013  05:49, Eugene M. Zheganin <emz@norma.perm.ru> a crit :

> You cannot do this with a pptp or l2tp, they just don't have that ability.

> Standard approach is either using remote pptp/l2tp peer as default gateway, or creating a sticky route on the client side.

Even if its not built-in the L2TP / PPTP standard, the rest of the world do it, and need it by the way. Using the VPN gateway as a default one is not acceptable when its made to secure access to specific resources only (i.e: Split Tunneling), as a provider, I dont want to handle all network traffic from road-warriors, I dont care about their FaceBook traffic, I just want they corporate one.

With VPN, also regularly come VPN on Demand, a settings on the client side allowing the system to automatically start VPN connection when the user request for a specific domain (like private.example.com). And if the authentication is fully based on certificate, the user dont see any authentication request.

This kind of highly demanded feature today cant be address if at the beginning we dont have split tunneling

Well, thats a big big problem for me and force me to review all my plan about this network and also with my OS X Server replacement project made from a standard FreeBSD

> You could do this using openvpn, but openvpn is a horrible mess of weirdness and incompatibility.

I agree with that, OpenVPN is such a mess And cant be deployed on all devices, for example, they have some problems to distribute their app in France on iOS devices. That the only one with that problem

[-- Attachment #2 --]
0	*H
010	+0	*H
00r'znn0
	*H
0o10	USE10U
AddTrust AB1&0$UAddTrust External TTP Network1"0 UAddTrust External CA Root0
050607080910Z
200530104838Z010	UUS10	UUT10USalt Lake City10U
The USERTRUST Network1!0Uhttp://www.usertrust.com1604U-UTN-USERFirst-Client Authentication and Email0"0
	*H
0
9}A;bF7`u9eJGHjM5BI/|1Nd.)բdąQ5yNh{zɤ2O0nFxoY^/m/묡j.g5yiF͠v:z'[=s"HaLi.1 ,׉CZqYں
gT:
wetbh~GeMW(t40b0,00U#0z4&&T$T0Ug}ĝ&pKPH|=n}0U0U00{Ut0r08642http://crl.comodoca.com/AddTrustExternalCARoot.crl06420http://crl.comodo.net/AddTrustExternalCARoot.crl0
	*H
؉o(~TBk	ĠmאfyCqovE7=YxFz[r-F)Iy<mmhOr6j5PρmUY0JmdI|6i9ZK:
D/p%ZTļms2,雄$-zhP?Mg.;N
&DeMR>k2\Al]Xm=G.̎00mOj3""2zq0
	*H
010	UUS10	UUT10USalt Lake City10U
The USERTRUST Network1!0Uhttp://www.usertrust.com1604U-UTN-USERFirst-Client Authentication and Email0
110428000000Z
200530104838Z010	UGB10UGreater Manchester10USalford10U
COMODO CA Limited1907U0COMODO Client Authentication and Secure Email CA0"0
	*H
0
[KW^/@ȣSX_fe2N2}UxLUB'qi2@'Vbqi c^`ʢAjHmeC*.+c8w߱ڂ2jgo \5Tq
7
PSlY1	LR@[HhJ$:q_㬿;%qh=XF<hmz!W42~JRrd&N`ohQcB}"cөΞD\[5K0G0U#0g}ĝ&pKPH|=n}0UzNt[xcd'/[y{0U0U00U 
00U 0XUQ0O0MKIGhttp://crl.usertrust.com/UTN-USERFirst-ClientAuthenticationandEmail.crl0t+h0f0=+01http://crt.usertrust.com/UTNAddTrustClient_CA.crt0%+0http://ocsp.usertrust.com0
	*H
־xWUm3DRB
JAIZҭsn>&|L0(B<%>
u=9fѡMo(ltZڱuz/yVtCr`9 G:eH<=%`I?C
3_н`j;:<I3B)93i.EMiڀ=]|Gm]W0KID~y83:]&XaU!ՙC@B0Ұun0*02'IP0
	*H
010	UGB10UGreater Manchester10USalford10U
COMODO CA Limited1907U0COMODO Client Authentication and Secure Email CA0
130303000000Z
140303235959Z0%1#0!	*H
	yoann.gini@gmail.com0"0
	*H
0
\紪o1n;ici`AO 3B3:Jol	/SEQ3b
8ijܹotoEiYҴ6ruOwn
 Drk|4)}PbæM5Ͻe!c .Uy3t"]4>+xxO?Vn57;CB%|'1e

+*_00U#0zNt[xcd'/[y{0U}qDU2X2M0U0U00 U%0++10	`HB 0FU ?0=0;+10+0)+https://secure.comodo.net/CPS0WUP0N0LJHFhttp://crl.comodoca.com/COMODOClientAuthenticationandSecureEmailCA.crl0+|0z0R+0Fhttp://crt.comodoca.com/COMODOClientAuthenticationandSecureEmailCA.crt0$+0http://ocsp.comodoca.com0U0yoann.gini@gmail.com0
	*H
-!8AM	!([".lA96PiJvSvubL)Yǂx\T
&K#SLќGۀ'wԺl8Άҕ	Zon/\">DAtK>ubKTPsV٨5yĬkNGVҙ|ĠdM_1vf.՛hGvM^K
=h,K"M-0t^1,To>100010	UGB10UGreater Manchester10USalford10U
COMODO CA Limited1907U0COMODO Client Authentication and Secure Email CA2'IP0	+0	*H
	1	*H
0	*H
	1
130319065650Z0#	*H
	1Er=]j0	+710010	UGB10UGreater Manchester10USalford10U
COMODO CA Limited1907U0COMODO Client Authentication and Secure Email CA2'IP0*H
	1010	UGB10UGreater Manchester10USalford10U
COMODO CA Limited1907U0COMODO Client Authentication and Secure Email CA2'IP0
	*H
*5L+<YX.*wsON"Zu9#d4s7O$K|9ˇ&{d\.L^K̔gcP7ooqtò
7CL5u?4=ߤ=Z"g] >L'OGoxVJd5{%Xh|&,zb.8Dv HmQi^蜹<:zUީ-쳟9%l8	

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?1306548A-C393-44DF-9B8D-9A34D806622E>