Firewall Wizards mailing list archives

RE: Placement of a VPN Appliance


From: Ben Nagy <ben.nagy () marconi com au>
Date: Fri, 5 Jan 2001 08:47:19 +1030

UDP encapsulated IPsec? Could you elaborate or direct me to 
where I can find
more about this? 

Not much to say, really. The concept is that you take the IPSec packet
you're about to send and wrap it in another UDP packet. All NAT etc gets
performed on the outer UDP wrapper. When the other VPN device receives the
packet it discards the wrapper and looks at the IP addressing on the IPSec
packet within - which will typically have private src/dest IPs.

What vendors are doing this

Checkpoint and Cisco (for their VPN concentrators only, at this stage, I
think) at least.

(I assume to 
allow VPNs to work
through NAT firewalls?)?

Yup.

thanks!

johnS

Cheers,

--
Ben Nagy
Marconi Services
Network Integration Specialist
Mb: +61 414 411 520  PGP Key ID: 0x1A86E304

_______________________________________________
firewall-wizards mailing list
firewall-wizards () nfr com
http://www.nfr.com/mailman/listinfo/firewall-wizards


Current thread: