Re: [Users] DHCP over IPSEC implemented?

From: Mikael Hammarin (mikael.hammarin_at_devtrend.com)
Date: Wed Jul 31 2002 - 00:11:00 CEST


Yes, I have now received the DHCP relay agent from Mario and I actually
managed to set the
first dynamically assigned IP-address to the SSH Sentinel client.

However, I seem to have some difficulties finding the correct configuration
for dhcpd.
When using dhcprelay on the ipsec0 interface (external IP) on my gateway to
relay to an internal DHCP server
on my private network (192.168.x.x), dhcpd will not allow me to assign an
IP-address except one from the gateway
external interface (ipsec0) as it was relayed from that IP-address.
Naturally, I would like to assign an IP-address from
another private subnetwork (192.168.x.x).

I would guess it is just a configuration error, but I must say that after
trying xxx configs I'm currently out of ideas and
would appreciate a hint on how to solve this issue.

regards,
Mikael

> >Hi all,
> >
> >A little bit confused. Is DHCP over IPSEC implemented in the current and
> latest version of x.509 patch or not?
> >If so, anyone got it working satisfactory?
> >
> >Managed to receive DHCP DISCOVER requests by using dhcpd on the ipsec
> interface when using SSH Sentinel,
> >but the reply to the actual request seemed not to be understood or
received
> by the SSH Sentinel client.
>
> Yes, the current version (0.9.14) supports DHCP over IPSec. The missing
link
> in your setup is the dhcp relay agent, which must reside on the gateway.
The
> agent is implemented and maintained by Mario Strasser of the Zurich
> University of Applied Sciences in Winterthur. He gave me a beta version
for
> testing purposes and it actually works fine.
>
> I think Mario will release a public version in the next weeks.
>
> Regrds, Adrian
>
>
>

_______________________________________________
Users mailing list
Users_at_lists.freeswan.org
http://lists.freeswan.org/mailman/listinfo/users



This archive was generated by hypermail 2.1.4 : Mon Aug 05 2002 - 21:01:34 CEST