[rhn-users] IPSec Questions

Smith Jr, Harry E harry.e.smith.jr at lmco.com
Tue Nov 8 16:35:12 UTC 2005


I am trying to deploy IPSec VPN using a RH4 box as the gateway and
router.  This is not the configuration in the RH4 System Admin or
Security Guide but is closer to the configuration in the IPSec Howto
Guilde. 

Red WKS ---> Red VPN NIC , Black VPN NIC --->  Black Network ----> Black
VPN NIC , Red VPN Nic ---> Red WKS

The Red and Black VPN NIC are on the same physical box.  The Red Network
is in the 172.x.x.x. and the black is in the 192.x.x.x.

So far that any configuration I try either fails or by-passes the
tunnel.

Here are my questions:

1. In setkey, if I have not used the -m tunnel on the add command but do
use esp/tunnel/IP1-IP2//require on the spdadd, is the Ipsec running is
tunnel or esp mode ?  

2. When I examine the Black VPN NIC with either ethereal or tcpdump,  I
see the red IP address, but I am not sure how is it going thru the
router. (Linksys 8 port for testing purposes set with the black
network).  Is Ethereal and TCPdump grabbing the data before it goes into
the tunnel ? 


Harry 

-------------------------------------------------------------
Harry E Smith Jr.
Senior Staff System Engineering
(408) 473 6491 (work)
(877) 635 1529 (pager)

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listman.redhat.com/archives/rhn-users/attachments/20051108/4d1daba9/attachment.htm>


More information about the rhn-users mailing list