Re: IPSEC documentation



Brian Candler <B.Candler@xxxxxxxxx> writes:

> OK, I'll buy gif + IPSEC transport mode as an option. [Although in that
> case, perhaps what you want is an external IPSEC tunnel mode implementation
> which attaches to a 'tun' device. That's yet another category which I hadn't
> even considered]

Any url describing this setup please ?

> I still think that gif + IPSEC tunnel mode (as currently documented) is not
> a good approach, especially if it's the *only* mode of operation to be
> documented and hence implicitly recommended as the 'right' way to do it.

Well, ipsec section of the handbook is probably not the best one, I'd
like to see it extended with the sections you talked about in this
thread. Maybe it's time to submit patches...

--
>pourkoi faire ca c koi le but? je vois pas l interet c un forum libre
>ou tt le monde px s exprimer c pas mtnt kil faut reagir c ds les posts
Au secours, mon ROT-13 ne marche plus :-((((
-+- PC in <http://www.le-gnu.net> : Neuneu decode à plein tube -+-
_______________________________________________
freebsd-net@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-net
To unsubscribe, send any mail to "freebsd-net-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: Firewall and VPN considerations
    ... I will also use the firewall's external side to connect with ipsec to ... other LAN which have Cisco VPN equipment. ... they say quad core does not raise the performance compared to duo core ... they suggest not to use gif together with ipsec to achive compatibility ...
    (freebsd-net)
  • Firewall and VPN considerations
    ... The firewall will also act as a VPN-gateway for external workstations running Windows XP Professional, I will use Microsoft's ipsec software included in the Windows XP. ... I will also use the firewall's external side to connect with ipsec to other LAN which have Cisco VPN equipment. ... In this thread http://lists.freebsd.org/pipermail/freebsd-net/2007-September/015290.html they say quad core does not raise the performance compared to duo core when building a router. ... In this thread http://lists.freebsd.org/pipermail/freebsd-net/2006-June/010909.html they suggest not to use gif together with ipsec to achive compatibility with cisco etc, so I'm planing to skip gif, wrong or right? ...
    (freebsd-net)
  • more on IPSec + gif stalling
    ... I've done another test on the IPSec + gif issue. ... Set up IPSec rules for both machines, created a gif tunnel between both ... IPSec + gif - firewall = just works ...
    (freebsd-net)
  • Re: IPSec tcp session stalling ( me too ) ...
    ... As soon as a gif interface is involved, ... checked with udp) session running inside the gif tunnel breaks. ... When either not using IPSec, not enabling pf or not using gif - ...
    (freebsd-net)
  • Re: IPSEC documentation
    ... It suggests that you encapsulate your packets in IP-IP (gif) ... > encapsulation and THEN encapsulate that again using IPSEC tunnel mode. ...
    (freebsd-net)