Date: Wed, 27 Aug 2003 08:45:23 -0700 From: Lars Eggert <larse@ISI.EDU> To: "Oldach, Helge" <Helge.Oldach@atosorigin.com> Cc: hilman firmansyah <hilman@nap.net.id> Subject: Re: Gif IPTunnel networkA-to-networkB not work Message-ID: <3F4CD213.40306@isi.edu> In-Reply-To: <D2CFC58E0F8CB443B54BE72201E8916EF41A70@dehhx005.hbg.de.int.atosorigin.com> References: <D2CFC58E0F8CB443B54BE72201E8916EF41A70@dehhx005.hbg.de.int.atosorigin.com>
index | next in thread | previous in thread | raw e-mail
[-- Attachment #1 --] Oldach, Helge wrote: > > You must have the networks connected (on the public side), but when > using IPSec your gif tunnel won't really be used. It is just sort of > a "placeholder" to get the routing correct. It is not a good idea to use gifs in parallel with IPsec tunnel mode., to do this routing trick. Please see the "options FAST_IPSEC & tunnels" thread on net@ from circa 4/1/2003. Basically, that approach creates two parallel virtual topologies, one out of IPIP tunnels, and one out of IPsec tunnel mode SAs. People often do this, because they want to route traffic into an IPsec tunnel, and the SA itself doesn't have a route entry, since they aren't devices. When using IPIP tunnels with tunnel mode, they abuse the route created by the gif device for routing, but packets will be hijacked by the tunnel mode SA, so they never actually enter gif processing (IPsec does the IPIP encapsulation internally.) Using IPIP tunnels with transport mode is valid, since packets will actually flow through the gif device, and get IPsec'ed after they are IPIP encapsulated. (In multihop topologies, they'll then need to be IPIP encapsulated again - the virtual network needs both virtual link and network layers.) It doesn't give you the full expressiveness of IPsec selectors, but it's good enough for many VPN schemes (and routing works!) See ftp://ftp.rfc-editor.org/internet-drafts/draft-touch-ipsec-vpn-05.txt. It is currently under in the IESG timeout before going to Informational. Lars -- Lars Eggert <larse@isi.edu> USC Information Sciences Institute [-- Attachment #2 --] 0 *H 010 + 0 *H 080fErtcvE.0 *H 010 UZA10UWestern Cape10U Cape Town10U Thawte Consulting1(0&UCertification Services Division1$0"UThawte Personal Freemail CA1+0) *H personal-freemail@thawte.com0 000830000000Z 040827235959Z010 UZA10UWestern Cape10U Cape Town10 U Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.3000 *H 0 32c %E>nx'gڈD)c5*mp<ܮto034qmOe KaU5u'rװ|CBPQ<9TIf - ki N0L0)U"0 010UPrivateLabel1-2970U0 0U0 *H 1KG]qSl]y=&b""I'{9$ *8PUl LGlX1B li+@]jy.%݊ Z<D&iHΥbb090 vo0 *H 010 UZA10UWestern Cape10U Cape Town10 U Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.300 030801172929Z 040731172929Z0T10 UEggert1 0U*Lars10ULars Eggert10 *H larse@isi.edu0"0 *H 0 >ן~H(ԢGV׆־25B03ݰת^RIH =%J kA^R)y H80P~qrU|c~\;ҋ^哪!֍&d@Cd"O"f$FrGe|r<z"%h+Z`3<}̘}9ʮcnb6RX ٫e~XgK7,ìEYU? V0T0*+e!0 00L2uMyffBNUbNJJcdZ2s0U0 larse@isi.edu0U0 0 *H 5Kkt[@jj:Fg Xj(8yPo!})5M[ ش]wʼnQd!GyFRiKd!8h\7γSD`a[qiY+Gqn?!090 vo0 *H 010 UZA10UWestern Cape10U Cape Town10 U Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.300 030801172929Z 040731172929Z0T10 UEggert1 0U*Lars10ULars Eggert10 *H larse@isi.edu0"0 *H 0 >ן~H(ԢGV׆־25B03ݰת^RIH =%J kA^R)y H80P~qrU|c~\;ҋ^哪!֍&d@Cd"O"f$FrGe|r<z"%h+Z`3<}̘}9ʮcnb6RX ٫e~XgK7,ìEYU? V0T0*+e!0 00L2uMyffBNUbNJJcdZ2s0U0 larse@isi.edu0U0 0 *H 5Kkt[@jj:Fg Xj(8yPo!})5M[ ش]wʼnQd!GyFRiKd!8h\7γSD`a[qiY+Gqn?!100010 UZA10UWestern Cape10U Cape Town10 U Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.30 vo0 + 0 *H 1 *H 0 *H 1 030827154523Z0# *H 1"Da2yE~#P0R *H 1E0C0 *H 0*H 0 *H @0+0 *H (0 +710010 UZA10UWestern Cape10U Cape Town10 U Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.30 vo0*H 1010 UZA10UWestern Cape10U Cape Town10 U Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.30 vo0 *H Z2?v%T*3Ew{QDLT5 Ghc9kIWY'1 Ɉr>._XrMnPvZ Fɉ0:(&Sbζ%Z'j˯l`1 Fe/20Lkm[Z,LJZ=G,Dkϖ<p ʬ wCrF{P?iЧo79 -Rqhelp
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3F4CD213.40306>
