Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: [Design] IPSec in 2.5 Kernel?

From: Derek Atkins <derek(at)ihtfp.com>
Date: Thu Mar 20 2003 - 02:39:48 EST

john,

> Where are the scalability and usability issues

You still have not defined what you mean by "scalabilty and usability issues." Do you mean the number of simultaneous IKE SAs? # of IPsec SAs? Packets per second? Mb/s?

> I don't understand why having an spdadd command

in.te.grate \'int-*-.gra-t\ vb [L integratus, pp. of integrare, fr.

   integr-, integer] 1: to form into a whole : UNITE 2a: to unite with    something else 2b: to incorporate into a larger unit 3: to find the    ...

When I download the kernel from kernel.org, I want IPsec to be a part of the download. *THAT* is integrated. If I have to download the IPsec stack separately then I've already lost.

Do you need help?X

> > You cannot .... successfully route

It's bit me. It's bit Phil Karn. It's bit a number of other people I know. I guess we don't count as "most users", but it just doesn't work for relatively simple (but non-standard) network architectures.

> b) The issues are fixable.

Maybe, but nobody has fixed them yet -- and the frees/wan people wont accept _my_ fixes.

> Well, maybe I've got a giant blind spot, but I've

Could you please describe what you mean here? What do you mean by "automatically-keyed subnet-to-subnets[sic] VPN"? Can you point me at an architectural picture that described this?

I _presume_ what you mean is that you've got a VPN gateway at a central location and bunch of extruded subnets going to a bunch of satellite offices? I also presume that the satellite offices are "road warriors" with non-static IP addresses.

If automatic keying means OE, then no, it obviously cannot use it. If "automatic keying" means "IKE with RSA without pre-shared keys", then yes, it can do that (although only with X.509 certs).

Do you need more help?X

> I get 5 hits (none useful) from:

If my presumption is correct above, and if you are NOT talking about OE, then yes, this is a goal of the project. But really the immediate goals are getting standards-compliant and feature complete IPsec into the mainline Linux kernel and supporting applications.

-derek

-- 
       Derek Atkins
       Computer and Internet Security Consultant
       derek@ihtfp.com             www.ihtfp.com
_______________________________________________
Design mailing list
Design@lists.freeswan.org
http://lists.freeswan.org/mailman/listinfo/design
Received on Thu Mar 20 03:02:42 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 12:59:57 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library