Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.misc > #5415

Re: PPTP and NAT, IPSec and vpnc to Draytek Vigor

From Chris Davies <chris-usenet@roaima.co.uk>
Newsgroups comp.os.linux.misc
Subject Re: PPTP and NAT, IPSec and vpnc to Draytek Vigor
Date 2012-05-24 23:54 +0100
Organization Roaima. Harrogate, North Yorkshire, UK
Message-ID <6qq299xpi7.ln2@news.roaima.co.uk> (permalink)
References (1 earlier) <jp7uct$1t8$1@dont-email.me> <9hov89xkj4.ln2@news.roaima.co.uk> <jplca7$9o4$1@dont-email.me> <1st199x5kt.ln2@news.roaima.co.uk> <jpll9b$g1i$1@dont-email.me>

Show all headers | View raw


J G Miller <miller@yoyo.org> wrote:
> On Thursday, May 24th, 2012, at 15:40:33h +0100, Chris Davies wrote:
>> What I'm finding most strange is that the private IP address for pcA on
>> my own LAN is being propagated into the network behind router2.

> You may think it strange but that is exactly what would should expect.

So what happens when my LAN address space happens to overlap the remote
address space and my PC has an IP address that clashes with something
on the remote side? That's a recipe for disaster, and surely there is
mitigation for the resulting mess?


> Remember IPSEC is like a tunnel and it starts from your PC, so the
> IP address associated with that will be your local private LAN address.

When I used to use a VPN client in a corporate (CISCO based) setting,
my local device was assigned an address from the VPN concentrator. To
me, this makes far more sense than exposing my private LAN address to
the remote network.


> [...] your traffic is still passing through your network device eth0.

Ah. Yes. I saw that, along with the policy based iptables rule (ouch).

I must admit, though, I really don't see why eth0 (or whatever) couldn't
have been assigned a temporary IP address from the VPN endpoint. I assume
there was good reason when IPSec was designed/implemented the way it is.


> With openvpn it is rather different becauase traffic then goes via a
> virtual device tun which does have a network address on each end different
> to the local network.

OpenVPN's default is to route rather than to bridge. I've never tried
it in bridging mode so I can't comment on what happens there.


> If you want to start doing complicated things with using different
> addresses to the local network, you can set up a GRE tunnel on top
> of the IPsec tunnel  ;)

Isn't the presence of GRE the reason why PPTP doesn't work (properly)
through a NAT router? I just don't want to go there!

Cheers,
Chris

Back to comp.os.linux.misc | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

PPTP and NAT, IPSec and vpnc to Draytek Vigor Chris Davies <chris-usenet@roaima.co.uk> - 2012-05-18 01:09 +0100
  Re: PPTP and NAT, IPSec and vpnc to Draytek Vigor Stan Bischof <stan@worldbadminton.com> - 2012-05-18 13:30 +0000
    Re: PPTP and NAT, IPSec and vpnc to Draytek Vigor Chris Davies <chris-usenet@roaima.co.uk> - 2012-05-19 01:07 +0100
      Re: PPTP and NAT, IPSec and vpnc to Draytek Vigor The Natural Philosopher <tnp@invalid.invalid> - 2012-05-19 01:16 +0100
  Re: PPTP and NAT, IPSec and vpnc to Draytek Vigor J G Miller <miller@yoyo.ORG> - 2012-05-19 10:58 +0000
    Re: PPTP and NAT, IPSec and vpnc to Draytek Vigor Chris Davies <chris-usenet@roaima.co.uk> - 2012-05-23 19:57 +0100
      Re: PPTP and NAT, IPSec and vpnc to Draytek Vigor J G Miller <miller@yoyo.ORG> - 2012-05-24 13:15 +0000
        Re: PPTP and NAT, IPSec and vpnc to Draytek Vigor Chris Davies <chris-usenet@roaima.co.uk> - 2012-05-24 15:40 +0100
          Re: PPTP and NAT, IPSec and vpnc to Draytek Vigor J G Miller <miller@yoyo.ORG> - 2012-05-24 15:49 +0000
            Re: PPTP and NAT, IPSec and vpnc to Draytek Vigor Chris Davies <chris-usenet@roaima.co.uk> - 2012-05-24 23:54 +0100
              Re: PPTP and NAT, IPSec and vpnc to Draytek Vigor J G Miller <miller@yoyo.ORG> - 2012-05-25 00:10 +0000
                Re: PPTP and NAT, IPSec and vpnc to Draytek Vigor Chris Davies <chris-usenet@roaima.co.uk> - 2012-05-25 08:51 +0100

csiph-web