Great Circle Associates Firewalls
(March 1998)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Linux Encrypted VPN
From: Maverick <docus @ m-net . arbornet . org>
Date: Thu, 5 Mar 1998 16:06:33 -0500 (EST)
To: ccurtis @ facm . fit . edu
Cc: firewalls @ GreatCircle . COM
In-reply-to: <Pine . LNX . 3 . 91 . 980305105618 . 30786A-100000 @ homer>

There was a nice article in SYSAdm sometime last year -- I think June 97
issue. Check it.


On Thu, 5 Mar 1998 ccurtis @
 facm .
 fit .
 edu wrote:

> I realize this is a bit off-topic, but since the VPN topic just popped up
> I figured I'd ask ... at least it's not spam.  ;-)
> 
> I was wondering if anyone had a HOWTO pointer or some general ideas on 
> how to create a VPN using Linux.  Ideally, the system should encapsulate 
> an IP packet (with a non-routable address) inside another packet as data, 
> fully (128bit) encrypted, which would then be tunnelled to another Linux 
> machine, to decrypt the packet and route it properly.  I know Linux will 
> do IP encapsulation (especially for the notebook users) but how would one 
> go about implementing an encryption layer in there?
> 
> Secondly, one of the key issues dealing with VPNs is authentication.  
> Sadly, I'm not terribly well versed in the OSI models et al, and don't 
> even know where to start in this respect.  Does the TCP layer have an 
> extra (or data) field that can store an auth-key, or would I have to use 
> a modificied TCP stack?  This system would use, of course, IPv4 ... 
> unless, of course, IPv4 could encapsulate an IPv6 packet that can be 
> authenticated against...
> 
> Ideas, suggestions?
> 
> Thanks,
> Chrisotopher
> 



References:
Indexed By Date Previous: SSL proxy?
From: Lee Mann <lmann @ uucom . com>
Next: Buffer Overflow
From: "J. Kris Baca" <kris . baca @ NWA . COM>
Indexed By Thread Previous: Re: Linux Encrypted VPN
From: Alexander Kjeldaas <astor @ guardian . no>
Next: AW: AW: Denial of Service [Was Re: Harsh Security audits?]
From: "Grutter H." <GRJN @ pggm . nl>

Google
 
Search Internet Search www.greatcircle.com