Re: [Openvpn-devel] ip/mac spoofing prevention

2005-06-08 Thread James Yonan
On Wed, 8 Jun 2005, Jason Lunz wrote: > If many clients are connected to a server-mode openvpn instance running > in bridge mode, any client can inject arbitrary ethernet frames onto the > VPN. By arbitrary, I mean that clients can change source mac and source > IP at will. This is a good thing; i

[Openvpn-devel] ip/mac spoofing prevention

2005-06-08 Thread Jason Lunz
If many clients are connected to a server-mode openvpn instance running in bridge mode, any client can inject arbitrary ethernet frames onto the VPN. By arbitrary, I mean that clients can change source mac and source IP at will. This is a good thing; it's flexible. However, this makes it useless t