Date: Mon, 30 Apr 2001 17:52:27 -0700 From: Lars Eggert <larse@ISI.EDU> To: "Michael C. Cambria" <cambria@mediaone.net> Cc: freebsd-net@freebsd.org Subject: Re: Tunnels & Route Advertisements Message-ID: <3AEE08CB.FB50F8CA@isi.edu> References: <3AEAEE6A.8AEAD76F@mediaone.net>
next in thread | previous in thread | raw e-mail | index | archive | help
[-- Attachment #1 --] > Should a tunnel endpoint show up in route advertisements sent from > rip/gated/zebra running on the FreeBSD 4.3-Stable system? Depends on if your routing protocol advertises over point-to-point links (like gif interfaces). If so, you should see virtual interfaces being advertised. > My guess is that for IPIP (e.g. gif interfaces), both remote endpoints > (outer IP address & inner IP address) are added to the local route table > since FreeBSD sees them as 2 interfaces. No. Adding a virtual interface adds one route for the virtual (= inner) IP address. The outer address is that of another interface, and thus already there. > It seems that ifconfig should > (or at least could) just add the route for gif0 just as it would for > xl0. Is this the case? Yes. (Look at netstat -r after an ifconfig on a gif.) > For _IPSec_ tunnels, I'm not as sure. I don't see any existing > mechinism that I'm familiar with such as ifconfig. Any ideas? IPsec tunnels (on FreeBSD) are not devices, and thus not represented in the routing table at all. Tunneling is done based on the IPsec SA database, which is separate and not integrated with the routing table at all. > I prefer IPSec tunnels for encryption of the internet, but can live (for > now) with IPIP if it does the job. IPsec transport mode combined with IPIP tunnels does the trick (dynamic routing + IPsec). See ftp://ftp.isi.edu/internet-drafts/draft-touch-ipsec-vpn-01.txt Lars -- Lars Eggert <larse@isi.edu> Information Sciences Institute http://www.isi.edu/larse/ University of Southern California [-- Attachment #2 --] 0# *H 010 + 0 *H 00A#0 *H 010 UZA10UWestern Cape10UDurbanville10 U Thawte10UCertificate Services1(0&UPersonal Freemail RSA 1999.9.160 000824203008Z 010824203008Z0T10 UEggert1 0U*Lars10ULars Eggert10 *H larse@isi.edu00 *H 0 \p9 H;vr∩6"C?mxfJf7I[3CF́L I - zHRVA怤2]0-bL)%X>nӅ w0u0*+e!0 00L2uMyffBNUbNJJcdZ2s0U0 larse@isi.edu0U0 0U#0`fUXFa#Ì0 *H _3 F=%nWY-HXD9UOc6ܰwf@uܶNԄR?Pr}E1֮23mFhySwM_h|d yR=$P 00}0 *H 010 UZA10UWestern Cape10U Cape Town10U Thawte Consulting1(0&UCertification Services Division1$0"UThawte Personal Freemail CA1+0) *H personal-freemail@thawte.com0 990916140140Z 010915140140Z010 UZA10UWestern Cape10UDurbanville10 U Thawte10UCertificate Services1(0&UPersonal Freemail RSA 1999.9.1600 *H 0 iZz]!#rLK~r$BRW{azr98e^eyvL>hput ,O 1ArƦ]D.Mօ>lx~@эWs0FO 7050U0 0U#0rIs4Uvr~wƲ0 *H kY1rr`HU{gapm¥7؝(V\uoƑlfq|ko!6- -mƃRt\~ orzg,ks nΝc) ~U100010 UZA10UWestern Cape10UDurbanville10 U Thawte10UCertificate Services1(0&UPersonal Freemail RSA 1999.9.16#0 + 0 *H 1 *H 0 *H 1 010501005227Z0# *H 18X(jv31x_A(0R *H 1E0C0 *H 0*H 0+0 *H @0 *H (0 *H j]sP.f]quoYn&s+ ,Z$#,y$ak0@R',!\8l9@ >zx~=z T0U)I>v;zyH&"}Jkz |
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3AEE08CB.FB50F8CA>
