Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 04 Apr 2002 08:52:16 -0800
From:      Lars Eggert <larse@ISI.EDU>
To:        Tariq Rashid <tariq@inty.net>
Cc:        Sam Leffler <sam@errno.com>, freebsd-net@freebsd.org, Joe Touch <touch@ISI.EDU>
Subject:   Re: kame ipsec vs. openbsd ipsec / netgraph ipsec node?
Message-ID:  <3CAC84C0.3000702@isi.edu>
References:  <MPENKFCCIIDAJKJJOLBHMEAJCNAA.tariq@inty.net>

next in thread | previous in thread | raw e-mail | index | archive | help

[-- Attachment #1 --]
Tariq Rashid wrote:
 > On a slightly side note, I'd much prefer to see FreeBSD with IPSEC
 > pseudo-interfaces a la OpenBSD/linux.
 >
 > I'd much prefer to work with say, enc0, or ipsec1, than mess around
 > with guf half-tunnels.... makes complex routing much easier....

Have you looked at draft-touch-ipsec-vpn 
(ftp://ftp.isi.edu/internet-drafts/draft-touch-ipsec-vpn-03.txt)? We 
address just this issue with a combination of IPsec transport mode and 
IPIP tunnels. We are currently revising it and it will move to 
Informational RFC soon.

Lars
-- 
Lars Eggert <larse@isi.edu>               Information Sciences Institute
http://www.isi.edu/larse/              University of Southern California

[-- Attachment #2 --]
0	*H
010	+0	*H
00G0
	*H
010	UZA10UWestern Cape10U	Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.300
010824164000Z
020824164000Z0T10
UEggert1
0U*Lars10ULars Eggert10	*H
	
larse@isi.edu00
	*H
0|\Pw v~~FDooӦA\-	 Cˀ4.)&{肋,z(ܷر߈T7_'txGH^tt/ҹB8%t<#ֲNV0T0*+e!000L2uMyffBNUbNJJcdZ2s0U0
larse@isi.edu0U00
	*H
aJPMՒ]cѭC+kS+wZ1gY",YT41
j6:~℩D~Kؚ‡l=u(ՎM?cF7@}T00G0
	*H
010	UZA10UWestern Cape10U	Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.300
010824164000Z
020824164000Z0T10
UEggert1
0U*Lars10ULars Eggert10	*H
	
larse@isi.edu00
	*H
0|\Pw v~~FDooӦA\-	 Cˀ4.)&{肋,z(ܷر߈T7_'txGH^tt/ҹB8%t<#ֲNV0T0*+e!000L2uMyffBNUbNJJcdZ2s0U0
larse@isi.edu0U00
	*H
aJPMՒ]cѭC+kS+wZ1gY",YT41
j6:~℩D~Kؚ‡l=u(ՎM?cF7@}T0)00
	*H
010	UZA10UWestern Cape10U	Cape Town10U
Thawte Consulting1(0&UCertification Services Division1$0"UThawte Personal Freemail CA1+0)	*H
	personal-freemail@thawte.com0
000830000000Z
020829235959Z010	UZA10UWestern Cape10U	Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.3000
	*H
032c	%E>nx'gڈD)c5*mp<ܮto034qmOe
KaU5u'rװ|CBPQ<9TIf-	kiN0L0)U"0 010UPrivateLabel1-2970U00U0
	*H
so&e4KYbDI

j&*bctmSK8P:l4撜n#	KrgPo.XPWՈ9[9}4%MjÑ/<RbH100010	UZA10UWestern Cape10U	Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.30G0	+a0	*H
	1	*H
0	*H
	1
020404165216Z0#	*H
	1ǃ̔_0R	*H
	1E0C0
*H
0*H
0
*H
@0+0
*H
(0*H
	1010	UZA10UWestern Cape10U	Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.30G0
	*H
%v_?4+MX!f)<<T+K *k6qiC+-x?~(	.Sxok`|]+;QHDG]Y

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3CAC84C0.3000702>