Subject: Re: rfc: gre over udp [patch]
To: Jonathan A. Kollasch <jakllsch@kollasch.net>
From: Jeff Rizzo <riz@NetBSD.org>
List: tech-net
Date: 08/26/2006 07:57:17
This is an OpenPGP/MIME signed message (RFC 2440 and 3156)
--------------enig6BCC13A9F4F9D7B34FDCF06F
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

Jonathan A. Kollasch wrote:
> On Sat, Aug 26, 2006 at 02:18:04AM -0500, David Young wrote:
>  =20
>> I need to tunnel packets through NAT routers to a tunnel concentrator =
at
>> my office.  To that end, I am extending gre(4) to put tunnel packets i=
nto
>> UDP datagrams.  I have attached a patch that contains my work in progr=
ess.
>> I request your feedback.
>>    =20
>
> Couldn't you just use tunnel-mode IPsec and NAT-T?  Or is the complexit=
y
> of IPsec/racoon trying to be avoided?
>
> 	Jonathan Kollasch
>  =20

I think the issue (if I understood it correctly) was the need to pass
through consumer-grade NAT devices which might not pass non-IP packets.

+j



--------------enig6BCC13A9F4F9D7B34FDCF06F
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (Darwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iQCVAwUBRPBhVLOuUtxCgar5AQMiXgP/X1HTaBbm5f9dMcmISJ5u1QnyPf+K7hrc
STzShkNXqCwUCMPBpf97O1PdXvvUAjdyME1RBHfMKgpYGAvQeg8pwN4fZFEkypiD
Q3oAheyrQmAOeK+iVIA1QAlHTLkY9Ad06J9ZNquvF5v3EREGpOaNb5unZAqMuOm3
iTORyQkvNPc=
=EDlB
-----END PGP SIGNATURE-----

--------------enig6BCC13A9F4F9D7B34FDCF06F--