|
Trick: Racoon Roadwarrior Configuration |
|
|
|
Tuesday, 21 November 2006 |
|
Roadwarrior is a client that uses unknown, dynamically assigned IP addresses to connect to a VPN gateway (in this case also firewall). This situation is shown on picture 1.1 and is one of the most interesting and today most needed scenarios in business environment.
In combination with racoon, roadwarrior scenario presents a few problems: - Client's IP address is unknown and cannot be defined in racoon.conf configuration file, or in the PSK keys file. Therefore, another way of client authentication is needed.
- It is not possible to define SPs according to which racoon on the gateway will behave, because destination address of the client is unknown. Racoon has to create any needed SPs or SAs when the connection is initiated.
Read more at Howtoforge |