Re: IPSec in 2.5 Kernel?
Derek Atkins <[email protected]> 20 Mar 2003 18:46:41 -0500
| Newsgroups | gmane.network.freeswan.devel |
|---|---|
| Message-ID | <[email protected]> |
John, "John S. Denker" <[email protected]> writes: > > then yes, it can do that (although only > > with X.509 certs). > > I'm delighted to hear it. > > But tell me, how does my security policy get set up > when my peers have non-static addresses? I know > about racoon's generate_policy option as mentioned > in e.g. I _believe_ that you can configure multiple "remote anonymous" sections, each with their own identities. I have never actually tested it, so it may not work right. It does appear that you must share the "sainfo" across all "anonymous" connections.... > http://www.qnx.com/developer/docs/momentics_nc_docs/neutrino/utilities/r/racoon.conf.html > > but my little brain doesn't see a convenient way to > make it secure. Suppose a peer that's supposed to > have access to one of my subnets wants access to > another of (or all of) my subnets. How do I prevent > this? I _believe_ you can just set the SPD to define what access is allowed. So for example you can say that 10.0.0.0/28 can only access 192.168.1.0/28, and 10.0.0.32/28 can only access 192.168.1.32/28.... I do need to take a closer look at road-warrior configurations to make sure they work. I have not had the chance to play with that yet, but I'll make sure to do so after I finish NAT-T. -derek -- Derek Atkins Computer and Internet Security Consultant [email protected] www.ihtfp.com