Thanks for sharing that note about DD-WRT broadcasting any packet that
is not UDP or TCP.
I wouldn't mind compiling a list of other home grade gateway/modems
that do or don't do the same, if anyone else has that info to share.
To clarify my note about securing with IPtables, I was referring to
the outside addresses. As in dropping all (non-44) inbound IP's that
are not listed as a gateway.
------Quote------
All,
A few points and questions:
1.) It's noted that IPIP does not traverse firewalls, that is not the
case with me, as I am traversing two firewalls to reach my Gateway
server, both devices using using DD-WRT, and it appears to broadcast any
packet that is not UDP or TCP. In fact, I also run a IPv6 tunnel on a
Vyatta instance in the same manner. Also, depending on the firewall's
NOS, it can be permitted through configuration (granted, you must have
control of that network device).
2.) KB9MWR asked if anyone was using a firewall or IPtables, I do
firewall my 44 Network, and only permit forwarding on that network for
44 hosts (i.e. someone could send an enscapsulated packet for any AMPR
subnet and it will be forwarded via my GW, all other IP addresses are
dropped at the firewall). I also restrict/permit services to certain /32
IP addresses, etc. In addition, some hosts on my network are only
available on AMPR and/or ACLs only permitting 44 hosts to use those
services (e.g. my DNS ACL permits full recursion for 44 hosts and allows
only 44.in-addr.arpa and
ampr.org resolution for all others).
3.) Would this VPN system allow me to use my 44Net allocation, or only
the allocation located at the VPN server itself?
4.) It is my understanding that the ARRL CA is not online, this would
require manual revocations, manual trusts (I'm not very familiar with
VPN via certificate)?
73,
Lynwood
KB3VWG