Re: letting traffic flow through a SG by default

"D. Hugh Redelmeier" <[email protected]> Tue, 11 Mar 2003 03:27:41 -0500 (EST)
Newsgroups gmane.network.freeswan.devel
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----


| From: D. Hugh Redelmeier <[email protected]>

| Management has decided that the behaviour Sam dislikes is a mistake.
| 
| In other words, by default, packets passing through the Security
| Gateway should not be blocked in any way.
| 
| The easiest way of implementing this is to say: any packet not subject
| to an eroute gets a free pass.
| 
| This can be implemented by the following in the "config setup"
| section:
| 
| 	packetdefault=pass
| 
| If this is the mechanism we use, this setting should become the
| default.
| 
| I propose that this become the default by being explicit in the
| /etc/ipsec.conf that is installed with FreeS/WAN.  This makes the
| danger somewhat more explicit.
| 
| I would leave the default value for the case where packetdefault is
| not specified in ipsec.conf to be "drop".
| 
| Comments?

[From conversation with MCR.]

- - management wants this behaviour when there are no config files.  So
  	packetdefault=pass
  must be the default, even without a config file.

- - I would still like this explicitly in the ipsec.conf we install "for
  free".  This would make the default visible.  It should be marked
  with a skull and crossbones.

Claudia: this will need to be carefully explained.

Hugh Redelmeier
[email protected]  voice: +1 416 482-8253

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3ia
Charset: noconv

iQCVAwUBPm2eAcFAuQPManGZAQFcXAP8DpenqJuFAqPpdF+iAYaLYEGRgdiD2qZj
Ge4j/eIsnyU2hCFlnzZEJIDE4/dD3i76nkIGkJXHcBqNRt+Ib4Ctji5iIroGglcj
zGyZRyywvUTvLxVcMNtQrzaVhhi4zJMdZX9z1wImPODKIXl2GefPZb2etQms65pN
OT6c31e58Rg=
=cvHW
-----END PGP SIGNATURE-----