letting traffic flow through a SG by default
"D. Hugh Redelmeier" <[email protected]> Mon, 10 Mar 2003 00:03:22 -0500 (EST)
| Newsgroups | gmane.network.freeswan.devel |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- | From: D. Hugh Redelmeier <[email protected]> | Subject: [Design] Sam's concerns about 2.00 | 1. If one just install FreeS/WAN 2.0 on a Security Gateway and does | nothing else, packets will be blocked in ways that might be | surprising, confusing, and unwanted. | | 1b Packets from nodes behind the SG will not get out because | (i) we've installed a default route to direct all packets from | the SG through ipsec0, and | (ii) there is no eroute for packets from behind the SG | The result is that the default policy will apply: %drop. Management has decided that the behaviour Sam dislikes is a mistake. In other words, by default, packets passing through the Security Gateway should not be blocked in any way. The easiest way of implementing this is to say: any packet not subject to an eroute gets a free pass. This can be implemented by the following in the "config setup" section: packetdefault=pass If this is the mechanism we use, this setting should become the default. I propose that this become the default by being explicit in the /etc/ipsec.conf that is installed with FreeS/WAN. This makes the danger somewhat more explicit. I would leave the default value for the case where packetdefault is not specified in ipsec.conf to be "drop". Comments? Hugh Redelmeier [email protected] voice: +1 416 482-8253 -----BEGIN PGP SIGNATURE----- Version: 2.6.3ia Charset: noconv iQCVAwUBPmwcn8FAuQPManGZAQH7hQP/RTbfHcUYCXAA9J6cYIvvgIucB1HZdvMC qfu3EGUuWcSwx9e5ODH886mX6OilJ6NNJzT0/6NuwZQftzZkOksFhYW3izYerWrx oiepC3+YCDKv1s0FcS/I0vC3CCP7R5T/Kp6/aYT1Ugr0LxJ/ZEoFzi7lNq5VdHNl X1dld+D+Bqk= =FFMy -----END PGP SIGNATURE-----