Date: Tue, 01 May 2001 12:08:47 -0700 From: Lars Eggert <larse@ISI.EDU> To: Gunther Schadow <gunther@aurora.regenstrief.org> Cc: snap-users@kame.net, freebsd-net@freebsd.org, ipfilter@coombs.anu.edu.au, altq@csl.sony.co.jp Subject: Re: The future of ALTQ, IPsec & IPFILTER playing together ... Message-ID: <3AEF09BF.9F9A7BAB@isi.edu> References: <3AEEEE79.8F7CC7B0@aurora.regenstrief.org> <3AEEF26B.C6850070@isi.edu> <3AEEF59D.3D5622DE@aurora.regenstrief.org> <3AEEFA06.BA0EB9FD@isi.edu> <3AEF0452.C2FD2651@aurora.regenstrief.org>
next in thread | previous in thread | raw e-mail | index | archive | help
[-- Attachment #1 --] Gunther Schadow wrote: > Another unknown to me is whether the GIF tunnel will copy > the TOS bits into the wrapper, and so, I can't use ALTQ at all. If it does not currently, this, at least, should be simple to add. > I just hope that in the future we will end up with a *consistent* set > of firewall, IPsec, and QoS networking facilities that can all play > together happyly and that can be managed at one point. I can see how > this could be done in two ways: VPNs took a while to understand and deploy for basic cases, and you're trying to apply pretty advanced stuff to them - there's bound to be some friction. The KAME guys do an amazing job with their networking stack, but their focus just isn't QoS over VPNs, it's IPv6 and IPsec deployment AFAIK. KAME is designed well enough to get you basic VPN functionality for free, but integration and combination testing with all these more exotic networking features eats up a lot of time. That's what we're for (wanting to use these things over VPNs :-). And the KAME people are extremely helpful and accessible when it comes to getting bug fixes (or feature-enabling mods) into their tree. Lars -- Lars Eggert <larse@isi.edu> Information Sciences Institute http://www.isi.edu/larse/ University of Southern California [-- Attachment #2 --] 0# *H 010 + 0 *H 00A#0 *H 010 UZA10UWestern Cape10UDurbanville10 U Thawte10UCertificate Services1(0&UPersonal Freemail RSA 1999.9.160 000824203008Z 010824203008Z0T10 UEggert1 0U*Lars10ULars Eggert10 *H larse@isi.edu00 *H 0 \p9 H;vr∩6"C?mxfJf7I[3CF́L I - zHRVA怤2]0-bL)%X>nӅ w0u0*+e!0 00L2uMyffBNUbNJJcdZ2s0U0 larse@isi.edu0U0 0U#0`fUXFa#Ì0 *H _3 F=%nWY-HXD9UOc6ܰwf@uܶNԄR?Pr}E1֮23mFhySwM_h|d yR=$P 00}0 *H 010 UZA10UWestern Cape10U Cape Town10U Thawte Consulting1(0&UCertification Services Division1$0"UThawte Personal Freemail CA1+0) *H personal-freemail@thawte.com0 990916140140Z 010915140140Z010 UZA10UWestern Cape10UDurbanville10 U Thawte10UCertificate Services1(0&UPersonal Freemail RSA 1999.9.1600 *H 0 iZz]!#rLK~r$BRW{azr98e^eyvL>hput ,O 1ArƦ]D.Mօ>lx~@эWs0FO 7050U0 0U#0rIs4Uvr~wƲ0 *H kY1rr`HU{gapm¥7؝(V\uoƑlfq|ko!6- -mƃRt\~ orzg,ks nΝc) ~U100010 UZA10UWestern Cape10UDurbanville10 U Thawte10UCertificate Services1(0&UPersonal Freemail RSA 1999.9.16#0 + 0 *H 1 *H 0 *H 1 010501190847Z0# *H 1|k!l"ڊ@r250R *H 1E0C0 *H 0*H 0+0 *H @0 *H (0 *H rrTm8QepygtZ>Zqd4#gӆ QSNȒoaE:D])dLAb2Tޝve0*<Mxq c9
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3AEF09BF.9F9A7BAB>
