[Users] "net-to-net" IPSec with only "gateway-to-gateway" tunneling

From: alphan (alphan3_at_yahoo.com)
Date: Tue Dec 10 2002 - 03:08:01 CET


folks,

i wondered if some of you could confirm this senario:

only gateway-to-gateway IPSec tunnel is set up (e.g.,
between FreeSWAN/Linux and Checkpoint FW-1/VPN-1),
instead of the full (end-to-end) net/host-to-net/host
tunnel. there are reasons not to set up in the latter
way....

are there people who have succeeded in setting up this
way and push the traffic through (clear text from
host1 to gateway1, then encrypted from gateway1 to
gateway2, followed by clear text again from gateway2
to host2)? of course one has to use NAT, etc. to make
the internal (clear-text) portion work.

any input sent to my email address will be highly
appreciated....and i'll summarize if i get enough
response.

cheers, -bill

__________________________________________________
Do you Yahoo!?
Yahoo! Mail Plus - Powerful. Affordable. Sign up now.
http://mailplus.yahoo.com
_______________________________________________
Users mailing list
Users_at_lists.freeswan.org
http://lists.freeswan.org/mailman/listinfo/users



This archive was generated by hypermail 2.1.5 : Wed Dec 11 2002 - 05:21:06 CET