Re: Freeswan Configuration

On Mon, Mar 25, 2002 at 01:23:08PM +1000, Bradley Marshall wrote:
> Note that this only works for the road warrior configuration.  To
> allow a DNS server that's on the freeswan end point in a subnet to
> subnet configuration to see these zones, you need to add the following
> to your named.conf options{} section:
>   listen-on {;; };
>   query-source address port *;
> where is the ip of the local ethernet device.  This will
> force any queries going out to use the local address, rather than

This is all well and good, apart from the fact that it breaks remote
name resolution.  To set this up properly, you need to create a VPN
from the client router to the office subnet.  See my reply message to
the explanation of the VPN setup at Dave and Berns place for an
example config.

