Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 01 May 2001 14:07:58 -0700
From:      Lars Eggert <larse@ISI.EDU>
To:        Gunther Schadow <gunther@aurora.regenstrief.org>
Cc:        snap-users@kame.net, freebsd-net@freebsd.org, ipfilter@coombs.anu.edu.au, altq@csl.sony.co.jp
Subject:   Re: The future of ALTQ, IPsec & IPFILTER playing together ...
Message-ID:  <3AEF25AE.56CF384A@isi.edu>
References:  <3AEEEE79.8F7CC7B0@aurora.regenstrief.org> <3AEEF26B.C6850070@isi.edu> <3AEEF59D.3D5622DE@aurora.regenstrief.org> <3AEEFA06.BA0EB9FD@isi.edu> <3AEF0452.C2FD2651@aurora.regenstrief.org> <3AEF09BF.9F9A7BAB@isi.edu> <3AEF2007.5968E10D@aurora.regenstrief.org>

next in thread | previous in thread | raw e-mail | index | archive | help

[-- Attachment #1 --]
Gunther Schadow wrote:
> Lars, what was your rationale for inventing the ip-tun package?

We wrote it a few years back for FreeBSD-3.X, to support X-Bone when no
KAME was installed (3.X did not have KAME code merged yet.) I hear there
are issues with it under 4.X due to a changed device model, but I think
we'll have a student port it over the summer. Then again, nos-tun(8)
supports IP-in-IP now, so maybe ip-tun is obsolete.

> Did you have good or bad experience with any of those alternatives?

Vtun uses UDP encapsulation, which means it's an application level thing
(like ssh tunnels). One of the major design objectives of X-Bone was to
use off-the-shelf, standardized OS mechanisms, so it didn't qualify.
We're trying to provide a pure IP overlay - ideally, you shouldn't be
able to tell an overlay network from a real network (e.g. ping,
traceroute, DNS, RIP, etc. all "just works"). Application-level tunnels
(and layer-2 tunnels) can't support this. (I also personnally don't
think UDP encapsulation has any purpose other than tunneling through
NATs, which are a bad hack and should die.) 

GRE encapsulation has functionality not needed for our purposes and adds
an extra header, so we decided against it.

I have no experience with pipsecd.

Lars
-- 
Lars Eggert <larse@isi.edu>               Information Sciences Institute
http://www.isi.edu/larse/              University of Southern California
[-- Attachment #2 --]
0#	*H
010	+0	*H
00A#0
	*H
010	UZA10UWestern Cape10UDurbanville10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 1999.9.160
000824203008Z
010824203008Z0T10
UEggert1
0U*Lars10ULars Eggert10	*H
	
larse@isi.edu00
	*H
0\p9޻ H;v֐r∩6"C?mxfJf7I[3CF́L	I
-zHRVA怤2]0-bL)%X>nӅw0u0*+e!000L2uMyffBNUbNJJcdZ2s0U0
larse@isi.edu0U00U#0`fUXFa#Ì0
	*H
_3	F=%nWY-HXD9UOc6ܰwf@uܶNԄR?Pr}E1֮23mFhySwM_h|d yR=$P 00}0
	*H
010	UZA10UWestern Cape10U	Cape Town10U
Thawte Consulting1(0&UCertification Services Division1$0"UThawte Personal Freemail CA1+0)	*H
	personal-freemail@thawte.com0
990916140140Z
010915140140Z010	UZA10UWestern Cape10UDurbanville10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 1999.9.1600
	*H
0iZz]!#rLK~r$BRW{azr98e^eyvL>hput,O	1ArƦ]D.Mօ>lx~@эWs0FO7050U00U#0rIs4Uvr~wƲ0
	*H
kY1rr`HU{gapm¥7؝(V\uoƑlfq|ko!6-	-mƃRt\~
orzg,ksnΝc)	~U100010	UZA10UWestern Cape10UDurbanville10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 1999.9.16#0	+0	*H
	1	*H
0	*H
	1
010501210758Z0#	*H
	12~Ulk$U	1 	O0R	*H
	1E0C0
*H
0*H
0+0
*H
@0
*H
(0
	*H
Ol,miI4f0gm'PJ	"|Tm-cS
uħmm b(?rC4"F2S)p GY{	/ʁ*
՘~B AZ)eZ/6

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3AEF25AE.56CF384A>