Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 22 Oct 1999 10:48:48 -0700 (PDT)
From:      Archie Cobbs <archie@whistle.com>
To:        mm@i.cz
Cc:        security@FreeBSD.ORG
Subject:   Re: GRE/IP 47/PPTP
Message-ID:  <199910221748.KAA67824@bubba.whistle.com>
In-Reply-To: <XFMail.991022154258.mm@i.cz> from Martin Machacek at "Oct 22, 1999 03:42:58 pm"

next in thread | previous in thread | raw e-mail | index | archive | help
Martin Machacek writes:
> Well, GRE tunnelling is something completely different from suporting GRE in
> NAT. I can imagine doing one-to-one NAT and passing GRE, but doing many to one
> NAT and supporting multiple GRE streams is IMHO impossible. There is no
> parameter in the GRE encapsulation that would allow you to identify the real
> internal recipient if you NAT multiple internal addresses to one external
> address.

True in general.. however, if all you're using GRE for is PPTP, then
you can multiplex on the call identifier in the PPTP/GRE header.

-Archie

___________________________________________________________________________
Archie Cobbs   *   Whistle Communications, Inc.  *   http://www.whistle.com


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?199910221748.KAA67824>