From owner-freebsd-net@FreeBSD.ORG Sat Oct 18 17:05:27 2008 Return-Path: Delivered-To: freebsd-net@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 8E6A71065687 for ; Sat, 18 Oct 2008 17:05:27 +0000 (UTC) (envelope-from sam@freebsd.org) Received: from ebb.errno.com (ebb.errno.com [69.12.149.25]) by mx1.freebsd.org (Postfix) with ESMTP id 6A5AE8FC0C for ; Sat, 18 Oct 2008 17:05:27 +0000 (UTC) (envelope-from sam@freebsd.org) Received: from trouble.errno.com (trouble.errno.com [10.0.0.248]) (authenticated bits=0) by ebb.errno.com (8.13.6/8.12.6) with ESMTP id m9IH5Rgb060040 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO) for ; Sat, 18 Oct 2008 10:05:27 -0700 (PDT) (envelope-from sam@freebsd.org) Message-ID: <48FA1756.1080708@freebsd.org> Date: Sat, 18 Oct 2008 10:05:26 -0700 From: Sam Leffler Organization: FreeBSD Project User-Agent: Thunderbird 2.0.0.9 (X11/20071125) MIME-Version: 1.0 To: freebsd-net@freebsd.org References: <200810181655.m9IGtxWk089117@freefall.freebsd.org> In-Reply-To: <200810181655.m9IGtxWk089117@freefall.freebsd.org> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit X-DCC--Metrics: ebb.errno.com; whitelist Subject: Re: conf/128030: [request] Isn't it time to enable IPsec in GENERIC? X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 18 Oct 2008 17:05:27 -0000 gavin@freebsd.org wrote: > Synopsis: [request] Isn't it time to enable IPsec in GENERIC? > > Responsible-Changed-From-To: freebsd-bugs->freebsd-net > Responsible-Changed-By: gavin > Responsible-Changed-When: Sat Oct 18 16:55:14 UTC 2008 > Responsible-Changed-Why: > Over to maintainer(s) for consideration > > http://www.freebsd.org/cgi/query-pr.cgi?pr=128030 > Last I checked IPSEC added noticeable overhead. Before anyone does this you need to measure the cost of having it enabled but not used. Sam