[63859] in North American Network Operators' Group
Re: Block all servers?
daemon@ATHENA.MIT.EDU (Steven M. Bellovin)
Sat Oct 11 13:42:05 2003
From: "Steven M. Bellovin" <smb@research.att.com>
To: Alex Yuriev <alex@yuriev.com>
Cc: nanog@merit.edu
In-Reply-To: Your message of "Sat, 11 Oct 2003 07:42:27 EDT."
<Pine.LNX.4.44.0310110741350.20543-100000@s1.yuriev.com>
Date: Sat, 11 Oct 2003 13:41:22 -0400
Errors-To: owner-nanog-outgoing@merit.edu
In message <Pine.LNX.4.44.0310110741350.20543-100000@s1.yuriev.com>, Alex Yurie
v writes:
>
>> Also what about folks who need to VPN in to their office
>> (either via PPTP or IPSEC)? How would you take care of that
>> situation?
>
>IPSEC works over NATs just fine.
>
Not in the general case, no. See draft-aboba-nat-ipsec-04.txt if you
can find a copy.
--Steve Bellovin, http://www.research.att.com/~smb