Date: Tue, 18 Jun 2002 08:15:58 -0700 From: Lars Eggert <larse@ISI.EDU> To: Christophe Prevotaux <c.prevotaux@hexanet.fr> Cc: net@freebsd.org Subject: Re: IPIP (kind of) with Payload Encryption only Message-ID: <3D0F4EAE.5090207@isi.edu> References: <20020618153956.2a9352fa.c.prevotaux@hexanet.fr> <200206181352.g5IDqqnq047326@whizzo.transsys.com> <3D0F4AFA.3000908@isi.edu> <20020618170639.3754910d.c.prevotaux@hexanet.fr>
next in thread | previous in thread | raw e-mail | index | archive | help
[-- Attachment #1 --]
Christophe Prevotaux wrote:
> I can use AH/ESP however since I am using a satellite link
> thru a modem/hub(NOC) that fiddles around with packets in order
> to optimize them , I can't encrypt the headers otherwise the
> optimizer can't see inside the packets and therefore can't see the
> headers , so no optimization is done ,and I end up with a 33,6Kbps
> like speed for the VPN , which is useless (at best 56Kbps).
You could try (transport mode) IPsec over a UDP tunnel, if your
middlebox mucks with the L4 headers. Then again, your middlebox probably
only "optimizes" TCP - have you benmarked TCP vs. UDP performance over
the link? (If so, you'll need to use a TCP tunnel.)
Lars
--
Lars Eggert <larse@isi.edu> USC Information Sciences Institute
[-- Attachment #2 --]
0 *H
010 + 0 *H
00G0
*H
010 UZA10UWestern Cape10U Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.300
010824164000Z
020824164000Z0T10
UEggert1
0U*Lars10ULars Eggert10 *H
larse@isi.edu00
*H
0 |\Pw v~~FDooӦA\- Cˀ4.)&{肋,z(ܷر߈T7_'txGH^tt/ҹB8%t<#ֲN V0T0*+e!0 00L2uMyffBNUbNJJcdZ2s0U0
larse@isi.edu0U0 0
*H
aJPMՒ ]cѭC+kS+wZ1gY",YT41
j6:~℩D~Kؚl=u(ՎM?cF7@}T00G0
*H
010 UZA10UWestern Cape10U Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.300
010824164000Z
020824164000Z0T10
UEggert1
0U*Lars10ULars Eggert10 *H
larse@isi.edu00
*H
0 |\Pw v~~FDooӦA\- Cˀ4.)&{肋,z(ܷر߈T7_'txGH^tt/ҹB8%t<#ֲN V0T0*+e!0 00L2uMyffBNUbNJJcdZ2s0U0
larse@isi.edu0U0 0
*H
aJPMՒ ]cѭC+kS+wZ1gY",YT41
j6:~℩D~Kؚl=u(ՎM?cF7@}T080fErtcvE.0
*H
010 UZA10UWestern Cape10U Cape Town10U
Thawte Consulting1(0&UCertification Services Division1$0"UThawte Personal Freemail CA1+0) *H
personal-freemail@thawte.com0
000830000000Z
040827235959Z010 UZA10UWestern Cape10U Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.3000
*H
0 32c %E>nx'gڈD)c5*mp<ܮto034qmOe
KaU5u'rװ|CBPQ<9TIf - ki N0L0)U"0 010UPrivateLabel1-2970U0 0U0
*H
1KG]qSl]y=&b""I'{9$
*8PUl
LGlX1B li+@]jy.%݊
Z<D&iHΥbb100010 UZA10UWestern Cape10U Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.30G0 + a0 *H
1 *H
0 *H
1
020618151558Z0# *H
1=@lYG,hg_d80R *H
1E0C0
*H
0*H
0
*H
@0+0
*H
(0*H
1010 UZA10UWestern Cape10U Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.30G0
*H
riI1p?oz\UsbKWo gD5mQ_Tyx-leU|'i OOG*wBiV;Bb"<k//PCdBپK z
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3D0F4EAE.5090207>
