Date: Tue, 01 Apr 2003 14:22:26 -0800 From: Lars Eggert <larse@ISI.EDU> To: Sam Leffler <sam@errno.com> Cc: Mailing List FreeBSD Network <freebsd-net@freebsd.org> Subject: Re: options FAST_IPSEC & tunnels Message-ID: <3E8A1122.5040304@isi.edu> In-Reply-To: <05b901c2f881$67e907f0$52557f42@errno.com> References: <86pto6mbxj.fsf@notbsdems.interne.kisoft-services.com> <05b901c2f881$67e907f0$52557f42@errno.com>
next in thread | previous in thread | raw e-mail | index | archive | help
[-- Attachment #1 --] On 4/1/2003 11:03 AM, Sam Leffler wrote: > > Long term, I intend is to associate packets with an enc device so > there's a way to identify these packets when writing firewall rules. Alternatively (and already working), you can replace IPsec tunnel mode with IPIP (gif) tunnels and transport mode, and then use the gif device in your firewall rules. It doesn't give you the full expressiveness of IPsec selectors, but it's good enough for many VPN schemes (and routing works!) (See ftp://ftp.rfc-editor.org/internet-drafts/draft-touch-ipsec-vpn-04.txt; I have the -05 update almost ready, which will then go to Informational.) Lars -- Lars Eggert <larse@isi.edu> USC Information Sciences Institute [-- Attachment #2 --] 0 *H 010 + 0 *H 080fErtcvE.0 *H 010 UZA10UWestern Cape10U Cape Town10U Thawte Consulting1(0&UCertification Services Division1$0"UThawte Personal Freemail CA1+0) *H personal-freemail@thawte.com0 000830000000Z 040827235959Z010 UZA10UWestern Cape10U Cape Town10 U Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.3000 *H 0 32c %E>nx'gڈD)c5*mp<ܮto034qmOe KaU5u'rװ|CBPQ<9TIf - ki N0L0)U"0 010UPrivateLabel1-2970U0 0U0 *H 1KG]qSl]y=&b""I'{9$ *8PUl LGlX1B li+@]jy.%݊ Z<D&iHΥbb090%A0 *H 010 UZA10UWestern Cape10U Cape Town10 U Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.300 020824185339Z 030824185339Z0T10 UEggert1 0U*Lars10ULars Eggert10 *H larse@isi.edu0"0 *H 0 6Fxΰ7aED&0+Dj)ֽXCUcnleijmz~S0J jWV~ 1^({IݛLjӖ ao:bP}WLVܱ욗cDɖ_Kv.A(W49;Z8-uXE 6b @_0%#d`Rto5 L0R`w@7 r Hcc U3%7N_o V0T0*+e!0 00L2uMyffBNUbNJJcdZ2s0U0 larse@isi.edu0U0 0 *H ]Ȕ,fK<cjRZeLan@Z6,= fK?yO#8+ Ni*LSfpQg<(aӒ$kTx_AL1>ގ|S090%A0 *H 010 UZA10UWestern Cape10U Cape Town10 U Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.300 020824185339Z 030824185339Z0T10 UEggert1 0U*Lars10ULars Eggert10 *H larse@isi.edu0"0 *H 0 6Fxΰ7aED&0+Dj)ֽXCUcnleijmz~S0J jWV~ 1^({IݛLjӖ ao:bP}WLVܱ욗cDɖ_Kv.A(W49;Z8-uXE 6b @_0%#d`Rto5 L0R`w@7 r Hcc U3%7N_o V0T0*+e!0 00L2uMyffBNUbNJJcdZ2s0U0 larse@isi.edu0U0 0 *H ]Ȕ,fK<cjRZeLan@Z6,= fK?yO#8+ Ni*LSfpQg<(aӒ$kTx_AL1>ގ|S100010 UZA10UWestern Cape10U Cape Town10 U Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.30%A0 + 0 *H 1 *H 0 *H 1 030401222226Z0# *H 1RÙ6ZբkUQ0R *H 1E0C0 *H 0*H 0 *H @0+0 *H (0 +710010 UZA10UWestern Cape10U Cape Town10 U Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.30%A0*H 1010 UZA10UWestern Cape10U Cape Town10 U Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.30%A0 *H esAod=WڎZ:V͛v ҟ+[<JhԒ^a]J'zDr)yI;LߌRQ4P/":$HJbg0p`^d?l쏣3#.9ő&lȡüh1K,;u$Wyq.o̮ =A^|ril;m:u7,?9WF-T0eJX
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3E8A1122.5040304>
