⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 requirement027.tex

📁 FREESWAN VPN源代码包
💻 TEX
字号:
\subsection{027: do not permit packets marked to tunnels to get loose}\subsubsection{027: Definition of requirement }There is a fundamental design flaw in the current FreeS/WAN KLIPSimplementation, specifically that it must rely on devices and routingbeing stable ({\bf always} up).  Worse there seems to be a bug (that RGB andMCR are currently chasing) that is stroking the flaw in at least FreeS/WANversion "1.9".The simple way to see both the flaw (and the result of the bug) istake a FreeS/WAN Security Gateway setup for VPN and issue the command:$$	ifconfig ipsec0 down$$and look closely at the results.  The bad thing that happens is thatall the routes put in for various CIDR's one wants to be 'secure' areremoved by the routing machinery.  Since the SG has a default route(in the dumb global routing table) it will get used for all thepackets that were (a moment ago) to be encrypted.This is a major security breach should it happen, and it can happenquite silently should the other ends your talking to not drop "in theclear" packets that should have been encrypted.Worse, many users don't notice this problem as a security failurebut write it off as a temporary network problem.  It's easy to see whytoo as the entire FreeS/WAN machinery continues to function, neverit's self noticing that it's not in use any more (for outgoingtraffic).\subsubsection{027: response}In the design work for a KLIPS replacement this will not be aproblem when running a vanilla box.

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -