letting traffic flow through a SG by default

"D. Hugh Redelmeier" <[email protected]> Mon, 10 Mar 2003 00:03:22 -0500 (EST)
Newsgroups gmane.network.freeswan.devel
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----


| From: D. Hugh Redelmeier <[email protected]>
| Subject: [Design] Sam's concerns about 2.00

| 1. If one just install FreeS/WAN 2.0 on a Security Gateway and does
|    nothing else, packets will be blocked in ways that might be
|    surprising, confusing, and unwanted.
| 

| 1b Packets from nodes behind the SG will not get out because
|    (i) we've installed a default route to direct all packets from
|        the SG through ipsec0, and
|    (ii) there is no eroute for packets from behind the SG
|    The result is that the default policy will apply: %drop.

Management has decided that the behaviour Sam dislikes is a mistake.

In other words, by default, packets passing through the Security
Gateway should not be blocked in any way.

The easiest way of implementing this is to say: any packet not subject
to an eroute gets a free pass.

This can be implemented by the following in the "config setup"
section:

	packetdefault=pass

If this is the mechanism we use, this setting should become the
default.

I propose that this become the default by being explicit in the
/etc/ipsec.conf that is installed with FreeS/WAN.  This makes the
danger somewhat more explicit.

I would leave the default value for the case where packetdefault is
not specified in ipsec.conf to be "drop".

Comments?

Hugh Redelmeier
[email protected]  voice: +1 416 482-8253

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3ia
Charset: noconv

iQCVAwUBPmwcn8FAuQPManGZAQH7hQP/RTbfHcUYCXAA9J6cYIvvgIucB1HZdvMC
qfu3EGUuWcSwx9e5ODH886mX6OilJ6NNJzT0/6NuwZQftzZkOksFhYW3izYerWrx
oiepC3+YCDKv1s0FcS/I0vC3CCP7R5T/Kp6/aYT1Ugr0LxJ/ZEoFzi7lNq5VdHNl
X1dld+D+Bqk=
=FFMy
-----END PGP SIGNATURE-----