OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
FreeBSD Security Archives: Re: GRE/IP 47/PPTP

Re: GRE/IP 47/PPTP


Martin Machacek (mmi.cz)
Fri, 22 Oct 1999 15:42:58 +0200 (MET DST)


On 22-Oct-99 Bert Kellerman wrote:
> You need to pass `-pptpalias <ipaddress>` on the command line. The ipaddress
> that you specify will be the only client/server on the inside that will get
> the type 47 packets. Check out the natd man page, it's all in there. AFAIK,
> cisco has supported GRE tunneling since IOS 9.x.

Well, GRE tunnelling is something completely different from suporting GRE in
NAT. I can imagine doing one-to-one NAT and passing GRE, but doing many to one
NAT and supporting multiple GRE streams is IMHO impossible. There is no
parameter in the GRE encapsulation that would allow you to identify the real
internal recipient if you NAT multiple internal addresses to one external
address.

        Martin

---
[PGP KeyID F3F409C4]

To Unsubscribe: send mail to majordomoFreeBSD.org with "unsubscribe freebsd-security" in the body of the message



This archive was generated by hypermail 2.0b3 on Fri Oct 22 1999 - 08:42:12 CDT