Mailinglist Archive: opensuse-security (465 mails)

< Previous Next >
Re: [suse-security] Masquerading IPSec through SuSE firewall
  • From: Mark Tinka <aknit44@xxxxxxxxxxx>
  • Date: Sat, 29 Dec 2001 20:22:20 +0000 (GMT)
  • Message-id: <20011229202220.45674.qmail@xxxxxxxxxxxxxxxxxxxxxxx>
this is true, however, provisions have been made with
the patch that allow IKE-based sessions to be
masqueraded, and generally, VPN sessions.. surely the
patch must have put this into consideration...

however, i think i should generalise and say, VPN
connections.. how can these be masq'ed..?..

thanks.. AKNIT

--- Torsten Mueller <torsten@xxxxxxxxxxxx> wrote: >
Hey,
>
> Mark Tinka schrieb:
> >
> > hi list...
> >
> > i have a user with a VPN client, Checkpoint, using
> the
> > IKE algorithm behind a SuSE 7.2 Pro system with a
> > stock 2.2.19 kernel, being masqueraded to the net
> > using ipchains....
> ...
>
> If i remember correctly, you can't use IPSec with
> masquerading,
> cause the IP Headers are changed in the masquerading
> and
> IPSec
> also sends a "checksum" which isn't o.k. after
> masquerading.
>
> But only my 2 cents.
>
> Torsten

__________________________________________________
Do You Yahoo!?
Everything you'll ever need on one web page
from News and Sport to Email and Music Charts
http://uk.my.yahoo.com

< Previous Next >
References