Re: IPSec in 2.5 Kernel?

"John S. Denker" <[email protected]> Thu, 20 Mar 2003 04:15:07 -0500
Newsgroups gmane.network.freeswan.devel
Message-ID <[email protected]>
On 03/20/2003 02:39 AM, Derek Atkins wrote:
 >
 > I _presume_ what you mean is that you've got a VPN gateway at
 > a central location and bunch of extruded subnets going to a
 > bunch of satellite offices?

Yes, that's what I mean when I speak of a subnet-to-subnets
VPN.

 > I also presume that the satellite
 > offices are "road warriors" with non-static IP addresses.

Yes, that's what I mean when I speak of dynamic
addresses.

 >  If "automatic keying" means "IKE with RSA without
 > pre-shared keys",

Yes, when I speak of automatic keying I mean IKE
as opposed to manual keying.  I forgot to mention
RSA but yes, that's what I had in mind.

 > then yes, it can do that (although only
 > with X.509 certs).

I'm delighted to hear it.

But tell me, how does my security policy get set up
when my peers have non-static addresses?  I know
about racoon's generate_policy option as mentioned
in e.g.

http://www.qnx.com/developer/docs/momentics_nc_docs/neutrino/utilities/r/racoon.conf.html

but my little brain doesn't see a convenient way to
make it secure.  Suppose a peer that's supposed to
have access to one of my subnets wants access to
another of (or all of) my subnets.  How do I prevent
this?