nanog mailing list archives

Re: Block all servers?


From: ken emery <ken () cnet com>
Date: Sat, 11 Oct 2003 14:11:09 -0700 (PDT)


On Sat, 11 Oct 2003, Steven M. Bellovin wrote:

In message <Pine.LNX.4.44.0310110741350.20543-100000 () s1 yuriev com>, Alex Yurie
v writes:

Also what about folks who need to VPN in to their office
(either via PPTP or IPSEC)?  How would you take care of that
situation?

IPSEC works over NATs just fine.

Not in the general case, no.  See draft-aboba-nat-ipsec-04.txt if you
can find a copy.

This internet draft is available at:

http://quimby.gnus.org/internet-drafts/draft-aboba-nat-ipsec-04.txt

I can't figure out if anything happened with this draft (I'm guessing
nothing went on).  The draft expired on December 1, 2001.

bye,
ken emery


Current thread: