Unix Technical Forum

IPsec: Why is ipencap needed in pf?

This is a discussion on IPsec: Why is ipencap needed in pf? within the comp.unix.bsd.openbsd.misc forums, part of the OpenBSD category; --> Hi everyone - Could anyone please tell me why the following line is needed when using ESP in tunnel ...


Go Back   Unix Technical Forum > Unix Operating Systems > OpenBSD > comp.unix.bsd.openbsd.misc

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-16-2008, 07:24 AM
news@redlamb.net
 
Posts: n/a
Default IPsec: Why is ipencap needed in pf?

Hi everyone -

Could anyone please tell me why the following line is needed when using
ESP in tunnel mode?

pass in on enc0 proto ipencap from $GATEWAY_B to $GATEWAY_A

I have been working my way through the vpn manpage and I understand
everything with the exception of this line. I have tried to google the
answer along with reading the RFCs with no luck.

If the enc interface allows an admin to see outgoing packets before
they have been processed by ipsec and incoming packets after they have
been processed, shouldn't an incoming packet, using ESP/tunnel, already
have the outside ip header stripped off?

Any help with understanding this issue would be greatly appreciated.
Thanks in advance.

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 09:41 AM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
www.UnixAdminTalk.com