Re: IPSec in 2.5 Kernel?

Derek Atkins <[email protected]> 20 Mar 2003 18:46:41 -0500
Newsgroups gmane.network.freeswan.devel
Message-ID <[email protected]>
John,

"John S. Denker" <[email protected]> writes:

>  > then yes, it can do that (although only
>  > with X.509 certs).
>
> I'm delighted to hear it.
> 
> But tell me, how does my security policy get set up
> when my peers have non-static addresses?  I know
> about racoon's generate_policy option as mentioned
> in e.g.

I _believe_ that you can configure multiple "remote anonymous"
sections, each with their own identities.  I have never actually
tested it, so it may not work right.  It does appear that you must
share the "sainfo" across all "anonymous" connections....

> http://www.qnx.com/developer/docs/momentics_nc_docs/neutrino/utilities/r/racoon.conf.html
> 
> but my little brain doesn't see a convenient way to
> make it secure.  Suppose a peer that's supposed to
> have access to one of my subnets wants access to
> another of (or all of) my subnets.  How do I prevent
> this?

I _believe_ you can just set the SPD to define what access
is allowed.  So for example you can say that 10.0.0.0/28
can only access 192.168.1.0/28, and 10.0.0.32/28 can only
access 192.168.1.32/28....

I do need to take a closer look at road-warrior configurations
to make sure they work.  I have not had the chance to play
with that yet, but I'll make sure to do so after I finish NAT-T.

-derek

-- 
       Derek Atkins
       Computer and Internet Security Consultant
       [email protected]             www.ihtfp.com