Re: How do I know my Connection is Encrypted.
James Cameron <[email protected]> Tue, 17 Apr 2012 16:19:05 +1000
| Newsgroups | gmane.network.poptop |
|---|---|
| Organization | Netrek Vanilla Server Dictator |
| Message-ID | <[email protected]> |
It depends. Some of the traffic representing your connections passes through pptpd, and some may not; it may pass through other network interfaces. This depends on how you have configured routing on the client. Some of the metadata exchanged between the client and the server is not encrypted. All of the IP packets are encrypted if pptpd is configured to use MPPE. The encryption is weak, in that it is RSA RC4 with only 128-bit session keys, and these keys depend on data elements that are initially exchanged in the clear. So I'm alarmed that you would ask, given how easily the encryption can be attacked. To answer your precise questions: a. no, the traffic between the server and the target that represents the connection between the client and the target, is not encrypted, b. yes, the traffic between the client and the server that represents your connection between the client and the target, is encrypted, if pptpd is properly configured, The simplified diagram on http://poptop.sourceforge.net/dox/diagnose-forwarding.phtml and the detailed diagrams that follow use a blue line, which is the line at the bottom of each diagram, to represent the connection between the client and the target. It doesn't represent the actual data flow. And your question: > If the server-target-client connections are not encrypted, is there > anyway to pass the connection back through the server? ... doesn't make sense to me, sorry. I think you might misunderstand my diagrams. ;-} -- James Cameron http://quozl.linux.org.au/ ------------------------------------------------------------------------------ Better than sec? Nothing is better than sec when it comes to monitoring Big Data applications. Try Boundary one-second resolution app monitoring today. Free. http://p.sf.net/sfu/Boundary-dev2dev