On Thu, 2016-03-31 10:39:03 -0400, Carter Browne wrote:
[..]
I didn't ask the reason why in this case - I have had instances where I wanted the communication to be encrypted, but I count not go directly from Host1 to Host3. If he can go directly from Host1 to Host3, then your configuration is correct. However, in these days of firewalls, network segmentation, etc. the direct path may not be available or desired.
Carter,
I was wondering if there is a reason for the two separately encrypted connections. I had the impression, an end-to-end-encryption and a port forwarder on Host2 was easier to set up (and more resource conserving), but this may be a matter of taste ...
Ludolf