Re: letting traffic flow through a SG by default
"D. Hugh Redelmeier" <[email protected]> Tue, 11 Mar 2003 03:27:41 -0500 (EST)
| Newsgroups | gmane.network.freeswan.devel |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- | From: D. Hugh Redelmeier <[email protected]> | Management has decided that the behaviour Sam dislikes is a mistake. | | In other words, by default, packets passing through the Security | Gateway should not be blocked in any way. | | The easiest way of implementing this is to say: any packet not subject | to an eroute gets a free pass. | | This can be implemented by the following in the "config setup" | section: | | packetdefault=pass | | If this is the mechanism we use, this setting should become the | default. | | I propose that this become the default by being explicit in the | /etc/ipsec.conf that is installed with FreeS/WAN. This makes the | danger somewhat more explicit. | | I would leave the default value for the case where packetdefault is | not specified in ipsec.conf to be "drop". | | Comments? [From conversation with MCR.] - - management wants this behaviour when there are no config files. So packetdefault=pass must be the default, even without a config file. - - I would still like this explicitly in the ipsec.conf we install "for free". This would make the default visible. It should be marked with a skull and crossbones. Claudia: this will need to be carefully explained. Hugh Redelmeier [email protected] voice: +1 416 482-8253 -----BEGIN PGP SIGNATURE----- Version: 2.6.3ia Charset: noconv iQCVAwUBPm2eAcFAuQPManGZAQFcXAP8DpenqJuFAqPpdF+iAYaLYEGRgdiD2qZj Ge4j/eIsnyU2hCFlnzZEJIDE4/dD3i76nkIGkJXHcBqNRt+Ib4Ctji5iIroGglcj zGyZRyywvUTvLxVcMNtQrzaVhhi4zJMdZX9z1wImPODKIXl2GefPZb2etQms65pN OT6c31e58Rg= =cvHW -----END PGP SIGNATURE-----