From owner-freebsd-security Thu Jan 24 12: 6:51 2002 Delivered-To: freebsd-security@freebsd.org Received: from ns.yogotech.com (ns.yogotech.com [206.127.123.66]) by hub.freebsd.org (Postfix) with ESMTP id DB93337B402 for ; Thu, 24 Jan 2002 12:06:45 -0800 (PST) Received: from caddis.yogotech.com (caddis.yogotech.com [206.127.123.130]) by ns.yogotech.com (8.9.3/8.9.3) with ESMTP id NAA18010; Thu, 24 Jan 2002 13:06:37 -0700 (MST) (envelope-from nate@yogotech.com) Received: (from nate@localhost) by caddis.yogotech.com (8.11.6/8.11.6) id g0OK6ag37633; Thu, 24 Jan 2002 13:06:36 -0700 (MST) (envelope-from nate) From: Nate Williams MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit Message-ID: <15440.26956.433891.236940@caddis.yogotech.com> Date: Thu, 24 Jan 2002 13:06:36 -0700 To: anderson@centtech.com Cc: dr3node , freebsd-security@FreeBSD.ORG Subject: Re: Can't set up an IPsec tunnel. In-Reply-To: <3C505AFD.52FF9ADE@centtech.com> References: <200201241847.AHX10883@vmms1.verisignmail.com> <3C50588C.7200324B@centtech.com> <200201241900.AHX11812@vmms1.verisignmail.com> <3C505AFD.52FF9ADE@centtech.com> X-Mailer: VM 6.96 under 21.1 (patch 14) "Cuyahoga Valley" XEmacs Lucid Reply-To: nate@yogotech.com (Nate Williams) Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org > As far as I know, no, because that would be like a "man in the middle" attack (I > think). Like this: > > A <--- B ---> C > > If A is talking to C via IPSEC, A tells C it's IP (the true IP) and C tells A > it's IP (its true IP, behind the masquaraded host), but A sees C as B's IP > address. How does it know that C knows that B exists? It doesn't matter, since B can't read/modify the traffic A or C generated. It can certainly mess with the headers all it wants, but that won't help it figure out what is going on. (Again, this assumes that A & C have authenticated themselves correctly, per the IPSEC specification. :) Nate > dr3node wrote: > > > > On Thursday 24 January 2002 21:55, you wrote: > > > IPSEC won't work through masquarading boxes or NAT firewalls. > > > > > > Eric > > > > is there any way way to cheat? > > > > To Unsubscribe: send mail to majordomo@FreeBSD.org > > with "unsubscribe freebsd-security" in the body of the message > > -- > ------------------------------------------------------------------ > Eric Anderson anderson@centtech.com Centaur Technology > If at first you don't succeed, sky diving is probably not for you. > ------------------------------------------------------------------ > > To Unsubscribe: send mail to majordomo@FreeBSD.org > with "unsubscribe freebsd-security" in the body of the message To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message