Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 13 Aug 2002 13:16:37 -0700
From:      Lars Eggert <larse@ISI.EDU>
To:        Julian Elischer <julian@elischer.org>
Cc:        Les Biffle <les@safety.net>, hackers@freebsd.org
Subject:   Re: IP routing question
Message-ID:  <3D596925.60906@isi.edu>
References:  <Pine.BSF.4.21.0208131245330.17577-100000@InterJet.elischer.org>

next in thread | previous in thread | raw e-mail | index | archive | help

[-- Attachment #1 --]
Julian Elischer wrote:
> On Tue, 13 Aug 2002, Les Biffle wrote:
>>I want to do the following:
>>
>>1.  Create "n" IPSEC VPN tunnels
>>2.  Create "n" VLAN pseudo interfaces
>>3.  Route IP Packets based on their arrival iface/tunnel out through
>>    a corresponding tunnel/iface.
>>
>>For example, I want to route all packets received through VPN tunnel "2"
>>out through VLAN "2," and all packets received on VLAN "2" out through
>>VPN "2," without regard to source or destination IP Addresses.
> 
> incoming packets should be selectabl in ipfw by using the 
> clause 
> "in recv gif0" 

Minor point: IPsec tunnel mode tunnels aren't gif tunnels - he'd need to 
use IPIP tunnels + IPsec transport mode in that case (see 
draft-touch-ipsec-vpn04.txt), which I recommend anyway, of course :-)

I hadn't thought of using the ipfw "in" selector, good idea!

Lars
-- 
Lars Eggert <larse@isi.edu>           USC Information Sciences Institute

[-- Attachment #2 --]
0	*H
010	+0	*H
00G0
	*H
010	UZA10UWestern Cape10U	Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.300
010824164000Z
020824164000Z0T10
UEggert1
0U*Lars10ULars Eggert10	*H
	
larse@isi.edu00
	*H
0|\Pw v~~FDooӦA\-	 Cˀ4.)&{肋,z(ܷر߈T7_'txGH^tt/ҹB8%t<#ֲNV0T0*+e!000L2uMyffBNUbNJJcdZ2s0U0
larse@isi.edu0U00
	*H
aJPMՒ]cѭC+kS+wZ1gY",YT41
j6:~℩D~Kؚ‡l=u(ՎM?cF7@}T00G0
	*H
010	UZA10UWestern Cape10U	Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.300
010824164000Z
020824164000Z0T10
UEggert1
0U*Lars10ULars Eggert10	*H
	
larse@isi.edu00
	*H
0|\Pw v~~FDooӦA\-	 Cˀ4.)&{肋,z(ܷر߈T7_'txGH^tt/ҹB8%t<#ֲNV0T0*+e!000L2uMyffBNUbNJJcdZ2s0U0
larse@isi.edu0U00
	*H
aJPMՒ]cѭC+kS+wZ1gY",YT41
j6:~℩D~Kؚ‡l=u(ՎM?cF7@}T080fErtcvE.0
	*H
010	UZA10UWestern Cape10U	Cape Town10U
Thawte Consulting1(0&UCertification Services Division1$0"UThawte Personal Freemail CA1+0)	*H
	personal-freemail@thawte.com0
000830000000Z
040827235959Z010	UZA10UWestern Cape10U	Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.3000
	*H
032c	%E>nx'gڈD)c5*mp<ܮto034qmOe
KaU5u'rװ|CBPQ<9TIf-	kiN0L0)U"0 010UPrivateLabel1-2970U00U0
	*H
1KG]qSl]y=&b""I'{9$
*8PUl
LGlX1B	li+@]jy.%݊
Z<D&iHΥbb100010	UZA10UWestern Cape10U	Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.30G0	+a0	*H
	1	*H
0	*H
	1
020813201637Z0#	*H
	1ƪZɃo+j0R	*H
	1E0C0
*H
0*H
0
*H
@0+0
*H
(0*H
	1010	UZA10UWestern Cape10U	Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.30G0
	*H
c*FN
usx6'>az:r{?*'Ӝf>5;C>k?,1۲9V*@m9f=i:c0X7_ZʡfRZ'

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3D596925.60906>