|
|||||||||||
|
Re: [Design] IPSec in 2.5 Kernel?
From: John S. Denker <jsd(at)monmouth.com>
Date: Thu Mar 20 2003 - 15:11:02 EST
On Thu, 20 Mar 2003, I wrote:
On 03/20/2003 02:02 PM, Jim Carter wrote:
Good point -- but changing the spelling doesn't change my conclusions. I get 26 hits from http://www.google.com/search?q=racoon+vpn+dhcp+documentation One of them looked like it might be useful http://www.sigsegv.cx/FreeBSD-WIN2K-IPSEC-HOWTO.html but in fact does not explain how to use KAME to set up a VPN with any semblance of security when the peer is using dynamic addresses (DHCP). I'm not trying to kindle a flame war. I'm just asking a question. Does anybody know how to use KAME to set up a secure VPN of the ordinary kind detailed in the previous msg? > "My module takes 4KB per connection" is more useful than > "your module won't scale".
You mean like this?
> And also important in such an analysis is the impact on the sysop,
Yes!!!! Also go through the life cycle for the not-quite clueless netadmin who's got N=200 or N=2000 IPsec endpoints. Make sure
I'm talking about manual workloads here. Work done by computers almost doesn't count, because computers are really fast. We should strive to do muuuuuch better than that. Setting up WEP features is beyond the ability of most people who buy wireless equipment. I base this assertion on data (so far unpublished AFAIK) acquired by driving around in metropolitan areas scanning for 802.11 signals and observing the level of security. Design mailing list Design@lists.freeswan.org http://lists.freeswan.org/mailman/listinfo/design Received on Thu Mar 20 16:51:54 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 12:59:57 EDT |
||||||||||
|
|||||||||||