IPSec SPD

Victor Sudakov sudakov at sibptus.tomsk.ru
Fri Oct 26 03:57:02 PDT 2007


Colleagues, 

Suppose our remote office uses the 10.1.1.0/24 network, and the whole
company uses the 10.0.0.0/8 network.

How do we set up the SPD entries to encrypt traffic to the
headquarters and back?

spdadd 10.0.0.0/8 10.1.1.0/24
...
spdadd 10.1.1.0/24 10.0.0.0/8
...

is not a good idea, is it? 

Thanks in advance for any input.

-- 
Victor Sudakov,  VAS4-RIPE, VAS47-RIPN
sip:sudakov at sibptus.tomsk.ru


More information about the freebsd-questions mailing list