[Shorewall-users] IPSec and VPN Appliance

Jonathan B. Bayer Jonathan B. Bayer" <jbayer@bayerfamily.net
Sat, 12 Jan 2002 08:04:35 -0500


------------28C51FF2F77828D
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hello Shorewall-users,

I have Shorewall installed as a firewall between our office and the net.
The internal network has an address range of 192.168.1.0/24

We are looking at purchasing a small VPN appliance to install at our
office.  I have two ways to install it.  The first (and preferred)
method is to install it on our local lan, and have the IPSec packets
transparently passed through the firewall directly to the appliance.
The second way is to put it side by side with the firewall, listening
on it's own address.

I'm not too happy about putting what is essentially a second firewall in
place, but am concerned about some problems I've heard about using IPSec
through a firewall which does NATing.

Any comments would be appreciated.

Thanks in advance.


JBB

 Jonathan B. Bayer                          mailto:jbayer@bayerfamily.net
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (MingW32)
Comment: For info see http://www.gnupg.org

iEYEARECAAYFAjxANGMACgkQLWek1tt+K52pCACfZSy/hZEGAYx5VYErpF95qxsy
IOgAnijxpFO/8EPN8H0pibiRRER7bXcy
=O34x
-----END PGP SIGNATURE-----
------------28C51FF2F77828D
Content-Type: text/x-vcard; name="vCard.vcf"
Content-Transfer-Encoding: 7bit
Content-Disposition: attachment; filename="vCard.vcf"

BEGIN:VCARD
VERSION:2.1
N:Bayer;Jonathan;B.;Mr.
FN:Jonathan B. Bayer
EMAIL;PREF;INTERNET:jbayer@spamcop.net
ORG:Dynamic Logic, Inc.
TITLE:Director of Technology
TEL;WORK;VOICE:(646) 742-4944
TEL;HOME;VOICE:(732) 283-2615
TEL;CELL;VOICE:(732) 423-3810
ADR;WORK:;;3 Park Ave., 37th Floor;New York;NY;10016;USA
LABEL;WORK;ENCODING=QUOTED-PRINTABLE:3 Park Ave., 37th Floor=0D=0ANew =
 York=0D=0ANY=0D=0A10016=0D=0AUSA
ADR;HOME:;;99 Trento St.;Iselin;NJ;08830;USA
LABEL;HOME;ENCODING=QUOTED-PRINTABLE:99 Trento St.=0D=0AIselin=0D=0ANJ=
 =0D=0A08830=0D=0AUSA
URL;WORK:www.dynamiclogic.com
REV:18991230T050000Z
END:VCARD
------------28C51FF2F77828D--