IPv6 readyNote: This archive passes through spamassassin. Every mail marked with the subject "*****SPAM*****" has exceed a certain threshold of spam-like behaviour.

[Users] SG placed in the destination subnet?

From: Matthias Beck (Matthias.Beck.AiT_at_t-online.de)
Date: Sat May 11 2002 - 18:22:35 CEST


Hi,

I'm using FreeS/Wan as Security-Gateway for Wireless Clients
(Windows 98/2k with SSH Sentinel) on my Access-Point. It works fine.

        Wired Net--------------Access-Point/SG------------Wireless
Client 1
                                        |
        
--------------------------Wireless Client 2

Because of performance reasons I want to move the SG in the wired net.
The problem is that I don't want to place the SG between the wired net
and the Access-Point because the Access-Point boots over network an its
NFS server is located in the wired net. So I want to do sth. like this:

        Switch--------------------Acess-Point------------Wireless Client
1
        | |
        |
-------------------Wireless Client 2
        |
        |---SG
        |
        |---Client1

Maybe Security-Gateway is the wrong expression now, perhaps VPN-Server
would be better. I tried to set the AP as default gateway for the
wireless
clients and started the ipsec tunnel to the SG but I wasn't able to
access
the wired net when I was dialed in. I also tried to do DNAT on the Acess
Point
but i didn't managed it to build a connection from the wireless clients.

So has anybody tried a similar setup? I think this is a quite common
problem
i.e. I don't think a company would merge the firewall and the SG and
they
also won't forward all traffic through the SG.

Any and all thoughts welcome.

_______________________________________________
Users mailing list
Users_at_lists.freeswan.org
http://lists.freeswan.org/mailman/listinfo/users



This archive was generated by hypermail 2.1.3 : Mon Jul 29 2002 - 05:19:58 CEST