Re: Cipe still vulnerable?
"Eric M. Hopper" <[email protected]> Wed, 23 Feb 2005 09:15:14 -0800
| Newsgroups | gmane.comp.encryption.cipe |
|---|---|
| Organization | Omnifarious Software |
| Message-ID | <[email protected]> |
On Wed, 2005-02-23 at 10:39 -0600, Les Mikesell wrote: > Is there an easy way to tell if a NAT device is NAT-T compatible? > Another alternative is OpenVPN, but it looks much more difficult to > configure, especially compared to the RedHat releases that included > CIPE and made it a fill-in-the-form setup. IPSEC NAT-T just puts the IPSEC packets inside UDP. By default it uses port 4500 for the tunneled packets. And, of course, it uses port 500 for IKE exchanges. Most NATs tunnel UDP by providing a temporary mapping that sends the packet back to the originator. So, NAT-T doesn't work well if both correspondents are behind a NAT, and neither side can set up any mappings on their NAT, but then again, neither does CIPE. Have fun (if at all possible), -- The best we can hope for concerning the people at large is that they be properly armed. -- Alexander Hamilton -- Eric Hopper ([email protected] http://www.omnifarious.org/~hopper) --
signature.asc
(application/pgp-signature, 185 B)
-----BEGIN PGP MESSAGE----- Version: GnuPG v1.2.6 (GNU/Linux) iD8DBQBCHLoijtsvlOwvazYRAr6iAJ45m5Q4ghbfRxshN9LAMhlcxsN8UQCfdm+H +BDUVEB71v4NUXZYQUDrWnM= =yjl/ -----END PGP MESSAGE-----