Re: best open NAT-T?
Philipp Buehler <[email protected]>
| Newsgroups | gmane.comp.security.vpn |
|---|---|
| Message-ID | <[email protected]> |
On 18/08/2003, David Newman <[email protected]> wrote To [email protected]: > For an IPSec gateway I'm building, which is the most robust/mature/stable > open-source code that supports NAT traversal? please note, that there are possible patent violations if this get's implemented: http://www.ietf.org/ietf/IPR/MICROSOFT-NAT-Traversal.txt and some other i've no URL at hand right now, it boils down that plain ESP-in-UDP is "free" but -in-TCP would require a checksum fixup of the inner TCP header after decrypt/decapsulation. > I am equally illiterate in FreeBSD, OpenBSD, and Linux, so platform choice > is not important. for OpenBSD there are inofficial patches, I'd send you - totally unsupported so far, of course :) > NAT-T support is required since we sometimes need to tunnel in from client > sites that themselves use NAT. <rant> Say thanks to the IETF that more and more patent "poisoned" techniques (which are almost pretty generic) can go into an official draft/rfc </rant> Ciao -- Philipp Buehler, aka fips | sysfive.com GmbH | BOfH | NUCH | <double-p> #1: Break the clue barrier! #2: Already had buzzword confuseritis ?