|
|||||||||||
|
Re: [Users] Can freeswan initiate connections automatically?
From: John J. Haluska <jhaluska(at)telcordia.com>
Date: Thu Mar 27 2003 - 09:58:50 EST John, So, are you saying that in the linux-to-cisco direction, I could use OE to accomplish this? I sort of ignored OE because it seemed to me that it would only work between freeswan boxes, maybe then this is not the case at all.
If what you are saying is correct, about being able to work with freeswan
at
Does OE work with transport mode as well as tunnel mode? Thanks much, John
"John S.
Denker" To: "John J. Haluska"
On 03/27/2003 08:31 AM, John J. Haluska wrote:
>
How many such boxes? > it's important to what I'm doing that the tunnels be set up at the
Why is this important? Unless you've got a huuuuge number of Cisco boxes, you will get better performance if you nail up the connections in advance. > My reading of the docs is that OE only works
OE does not require freeswan at both ends. Assuming you've got freeswan at "this" end, all you need is rfc-compliant IPsec at the far end, plus (!) control of the reverse DNS for the wild-side address of the far end. The OE initiator obviously needs a database of keying material, and right now the only type of database supported by freeswan is DNS. If (against repeated advice) you insist on using on-demand connections, and you can't get proper control of the reverse DNS, you can run named(8) on each freeswan box and brutally take control (locally) of the relevant reverse DNS entries. Users mailing list Users@lists.freeswan.org http://lists.freeswan.org/mailman/listinfo/users Received on Thu Mar 27 21:39:46 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 13:01:11 EDT |
||||||||||
|
|||||||||||