Re: Transport Mode IPSEC

2007-01-18 Thread Ted Mittelstaedt
- Original Message - From: "Andrew Pantyukhin" <[EMAIL PROTECTED]> To: "Ted Mittelstaedt" <[EMAIL PROTECTED]> Cc: "Dan Mahoney, System Admin" <[EMAIL PROTECTED]>; <[EMAIL PROTECTED]> Sent: Thursday, January 18, 2007 2:07 AM

Re: Transport Mode IPSEC

2007-01-18 Thread Andrew Pantyukhin
AIL PROTECTED]> Sent: Thursday, January 18, 2007 12:25 AM Subject: Re: Transport Mode IPSEC > On 1/18/07, Ted Mittelstaedt <[EMAIL PROTECTED]> wrote: > > Dan, > > > > You do realize, don't you, that since both of these hosts are on a switch, > > and ar

Re: Transport Mode IPSEC

2007-01-18 Thread Andrew Pantyukhin
On 1/18/07, Dan Mahoney, System Admin <[EMAIL PROTECTED]> wrote: On Thu, 18 Jan 2007, Andrew Pantyukhin wrote: > On 1/18/07, Dan Mahoney, System Admin <[EMAIL PROTECTED]> wrote: > > It's not that simple. The difficulty is in key exchange, > and it stays. I can show you how to implement it with >

Re: Transport Mode IPSEC

2007-01-18 Thread Ted Mittelstaedt
- Original Message - From: "Andrew Pantyukhin" <[EMAIL PROTECTED]> To: "Ted Mittelstaedt" <[EMAIL PROTECTED]> Cc: "Dan Mahoney, System Admin" <[EMAIL PROTECTED]>; <[EMAIL PROTECTED]> Sent: Thursday, January 18, 2007 12:25 AM

Re: Transport Mode IPSEC

2007-01-18 Thread Ted Mittelstaedt
EMAIL PROTECTED]> To: "Ted Mittelstaedt" <[EMAIL PROTECTED]> Cc: <[EMAIL PROTECTED]> Sent: Thursday, January 18, 2007 12:06 AM Subject: Re: Transport Mode IPSEC > On Wed, 17 Jan 2007, Ted Mittelstaedt wrote: > > > Dan, > > > > You do realize, don&#

Re: Transport Mode IPSEC

2007-01-18 Thread Dan Mahoney, System Admin
On Thu, 18 Jan 2007, Andrew Pantyukhin wrote: On 1/18/07, Dan Mahoney, System Admin <[EMAIL PROTECTED]> wrote: It's not that simple. The difficulty is in key exchange, and it stays. I can show you how to implement it with static keys: As I read through the article (http://www.freebsd.org/doc

Re: Transport Mode IPSEC

2007-01-18 Thread Andrew Pantyukhin
On 1/18/07, Dan Mahoney, System Admin <[EMAIL PROTECTED]> wrote: Hey all, I see the handbook has a nice howto on tunnel mode ipsec. I just want to protect my NFS/NIS traffic between two hosts on a switch (neither NAT'd) -- is there a reference as to transport-mode ipsec anywhere, or has anyone

Re: Transport Mode IPSEC

2007-01-18 Thread cknipe
Quoting Ted Mittelstaedt <[EMAIL PROTECTED]>: > > Most people don't wear 2 condoms, you know. Then you're not having wild enough sex -grin- :) -- C ___ freebsd-questions@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-que

Re: Transport Mode IPSEC

2007-01-18 Thread Dan Mahoney, System Admin
On Wed, 17 Jan 2007, Ted Mittelstaedt wrote: Dan, You do realize, don't you, that since both of these hosts are on a switch, and are using unicast traffic to communicate with each other, that they cannot be sniffed, don't you? That implies trust of the switch, trust against arp-cache poison

Re: Transport Mode IPSEC

2007-01-18 Thread Andrew Pantyukhin
On 1/18/07, Ted Mittelstaedt <[EMAIL PROTECTED]> wrote: Dan, You do realize, don't you, that since both of these hosts are on a switch, and are using unicast traffic to communicate with each other, that they cannot be sniffed, don't you? You might read up on ethernet switching technology a

Re: Transport Mode IPSEC

2007-01-17 Thread Ted Mittelstaedt
Dan, You do realize, don't you, that since both of these hosts are on a switch, and are using unicast traffic to communicate with each other, that they cannot be sniffed, don't you? You might read up on ethernet switching technology a bit before answering that. Most people don't wear 2 con