From owner-freebsd-net@FreeBSD.ORG Wed Dec 28 18:50:40 2005 Return-Path: X-Original-To: freebsd-net@freebsd.org Delivered-To: freebsd-net@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 6016C16A41F for ; Wed, 28 Dec 2005 18:50:40 +0000 (GMT) (envelope-from julian@elischer.org) Received: from a50.ironport.com (a50.ironport.com [63.251.108.112]) by mx1.FreeBSD.org (Postfix) with ESMTP id 9EE9143D5E for ; Wed, 28 Dec 2005 18:50:39 +0000 (GMT) (envelope-from julian@elischer.org) Received: from unknown (HELO [10.251.17.229]) ([10.251.17.229]) by a50.ironport.com with ESMTP; 28 Dec 2005 10:50:39 -0800 X-IronPort-Anti-Spam-Filtered: true Message-ID: <43B2DE7E.5080707@elischer.org> Date: Wed, 28 Dec 2005 10:50:38 -0800 From: Julian Elischer User-Agent: Mozilla/5.0 (Macintosh; U; PPC Mac OS X Mach-O; en-US; rv:1.7.11) Gecko/20050727 X-Accept-Language: en-us, en MIME-Version: 1.0 To: Brian Candler References: <20051228143817.GA6898@uk.tiscali.com> <86lky5p7ik.fsf@srvbsdnanssv.interne.kisoft-services.com> <20051228155545.GA7166@uk.tiscali.com> In-Reply-To: <20051228155545.GA7166@uk.tiscali.com> Content-Type: text/plain; charset=us-ascii; format=flowed Content-Transfer-Encoding: 7bit Cc: freebsd-net@freebsd.org Subject: Re: IPSEC documentation X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 28 Dec 2005 18:50:40 -0000 Brian Candler wrote: >On Wed, Dec 28, 2005 at 04:26:43PM +0100, Eric Masson wrote: > > >>gif/gre tunnels and ipsec transport mode are quite convenient when >>associated with dynamic routing protocols. >> >> > >OK, I'll buy gif + IPSEC transport mode as an option. [Although in that >case, perhaps what you want is an external IPSEC tunnel mode implementation >which attaches to a 'tun' device. That's yet another category which I hadn't >even considered] > > I use ppp (mpd) over UDP over ipsec transport mode. That gives you a "ng0" interface for the tunnel. (netgraph pseudo interface) >I still think that gif + IPSEC tunnel mode (as currently documented) is not >a good approach, especially if it's the *only* mode of operation to be >documented and hence implicitly recommended as the 'right' way to do it. >_______________________________________________ >freebsd-net@freebsd.org mailing list >http://lists.freebsd.org/mailman/listinfo/freebsd-net >To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org" > >