Re: IPSec in 2.5 Kernel?
"John S. Denker" <[email protected]> Thu, 20 Mar 2003 04:15:07 -0500
| Newsgroups | gmane.network.freeswan.devel |
|---|---|
| Message-ID | <[email protected]> |
On 03/20/2003 02:39 AM, Derek Atkins wrote: > > I _presume_ what you mean is that you've got a VPN gateway at > a central location and bunch of extruded subnets going to a > bunch of satellite offices? Yes, that's what I mean when I speak of a subnet-to-subnets VPN. > I also presume that the satellite > offices are "road warriors" with non-static IP addresses. Yes, that's what I mean when I speak of dynamic addresses. > If "automatic keying" means "IKE with RSA without > pre-shared keys", Yes, when I speak of automatic keying I mean IKE as opposed to manual keying. I forgot to mention RSA but yes, that's what I had in mind. > then yes, it can do that (although only > with X.509 certs). I'm delighted to hear it. But tell me, how does my security policy get set up when my peers have non-static addresses? I know about racoon's generate_policy option as mentioned in e.g. http://www.qnx.com/developer/docs/momentics_nc_docs/neutrino/utilities/r/racoon.conf.html but my little brain doesn't see a convenient way to make it secure. Suppose a peer that's supposed to have access to one of my subnets wants access to another of (or all of) my subnets. How do I prevent this?