Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

IPSEC VPNs (and others) have the remote networks defined in the protocol as part of the security association (SA). The SAs define which networks are available over the tunnel.

Saying "all RFC1918 addresses are available over here" is quite a cocky and obviously broken thing to do, unless you're dealing with a corporate device which is paranoid about leaking traffic to other networks.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: