nanog mailing list archives
Re: VPN recommendations?
From: Nathan Angelacos <nangel () tetrasec net>
Date: Sat, 12 Feb 2022 19:36:50 -0500
On Sat, 2022-02-12 at 13:24 -0700, Grant Taylor via NANOG wrote:
On 2/11/22 12:35 PM, William Herrin wrote:The thing to understand is that IPSec has two modes: transport and tunnel. Transport is between exactly two IP addresses while tunnel expects a broader network to exist on at least one end.That is (syntactically) correct. However, it is possible to NAT many LAN IPs (say RFC 1918) to one single Internet IP (say from a SOHO ISP) and use IPSec /Transport/ Mode to a single remote IP. The IPSec sees exactly two IPs."Tunnel" mode is what everyone actually usesI may be enough of an outlier that I'm a statistical anomaly. But I'm using IPSec /Transport/ Mode between my home router and my VPSs. I have a tiny full mesh of IPSec /Transport/ Mode connections.
+1 on *cough* enterprise networks.
Using the aforementioned many-to-one NAT, my home LAN systems access the single globally routed IP of each of my VPSs without any problem.
+1
Aside: I did have to tweak MTU for LAN traffic going out to the VPS IPs.
+1
So -1 for '"Tunnel" mode is what everyone actually uses', and +1 for /Transport/ Mode
+1
Current thread:
- VPN recommendations? William Herrin (Feb 10)
- RE: VPN recommendations? David Guo via NANOG (Feb 10)
- Re: VPN recommendations? Mike Lyon (Feb 10)
- Re: VPN recommendations? joy (Feb 10)
- Re: VPN recommendations? Dan Sneddon (Feb 11)
- Re: VPN recommendations? Mel Beckman (Feb 11)
- Re: VPN recommendations? William Herrin (Feb 11)
- Re: VPN recommendations? Christian de Larrinaga via NANOG (Feb 12)
- Re: VPN recommendations? Grant Taylor via NANOG (Feb 12)
- Re: VPN recommendations? Nathan Angelacos (Feb 12)
- Re: VPN recommendations? William Herrin (Feb 12)
- Re: OT: IPSec Transport vs Tunnel modes (Was: VPN recommendations?) Grant Taylor via NANOG (Feb 15)
- Re: OT: IPSec Transport vs Tunnel modes (Was: VPN recommendations?) Crist Clark (Feb 16)
- Re: VPN recommendations? Mike Lyon (Feb 10)
- RE: VPN recommendations? David Guo via NANOG (Feb 10)
- Re: VPN recommendations? John Gilmore (Feb 10)
- Re: VPN recommendations? Dave Taht (Feb 10)
- Re: VPN recommendations? Sean Kelly (Feb 10)
- Re: VPN recommendations? William Herrin (Feb 10)
- Re: VPN recommendations? Ander Punnar (Feb 10)
- Re: VPN recommendations? Mike Hammett (Feb 11)