Re: Raw doc in the policy group files
Claudia Schmeing <[email protected]> Tue, 18 Feb 2003 02:32:52 -0500
| Newsgroups | gmane.network.freeswan.devel |
|---|---|
| Message-ID | <20030218023252.O7052@raven> |
-----BEGIN PGP SIGNED MESSAGE----- Hi Hugh, What do you think of this to replace the first section of policygroups.html? Does it say all that needs saying by way of introduction, or does it require more fleshing out? Policy Groups are an elegant general mechanism to configure FreeS/WAN IPsec. They are useful for about 95% of IPsec applications. In the 1.x configuration model, in order to build IPsec connections between pairs of nodes, you needed to configure a connection for each pair. This made IPsec configuration an n-squared affair, and often resulted in long, complex /etc/ipsec.conf files. By contrast, Policy Groups allow you to set local IPsec policy for lists of remote CIDRs (names, IPs or groups of IPs), simply by mentioning the CIDR in the approriate Policy Group file. Linux FreeS/WAN then internally creates the connections needed to implement that policy. In the next section we describe our five Base Policy Groups, which you can use to configure IPsec in many useful ways. Cheers, Claudia -----BEGIN PGP SIGNATURE----- Version: 2.6.3ia Charset: noconv iQCVAwUBPlHhi3DIYXPDEHodAQHtMQP/Rl+gAaxIbQloVeLxnKO8M5MjCj6d+XBg hWh6ZiFKEFkf8IVloisJRmOxvH/UQDnxDTgzALcpHwayXETrSWCfBrRxwvZHYyd6 DRQK2Ciwz1CfLceor2H0FIH1T4ffK8j7zc5Jnue7OTRk5/JYRGHkslTCdW0XcYww s+4ZCERZNII= =vve3 -----END PGP SIGNATURE-----