Re: Raw doc in the policy group files

Hugh Daniel <[email protected]> Mon, 17 Feb 2003 23:57:47 -0800
Newsgroups gmane.network.freeswan.devel
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----

  Mz. Schmeing asked for some feedback on 2.00-notquiteyet doc, here
it is:

>  Policy  Groups are an elegant general mechanism to configure FreeS/WAN
>  IPsec. They are useful for about 95% of IPsec applications.

  I would say for ~'maybe' 95% of 'FreeSWAN' 'users'.~ or some such.

>  In  the  1.x  configuration model, in order to build IPsec connections
>  between  pairs of nodes, you needed to configure a connection for each
>  pair.  This  made  IPsec  configuration an n-squared affair, and often
>  resulted in long, complex /etc/ipsec.conf files.

  I would say ~In previous FreeS/WAN~ and say something about having
to do it at each end.  Keep it short though, as we can't afford to
bore folks, they might switch channels...
  I would trim the second sentacne down and just say it was a messy
pain.

>  By  contrast,  Policy  Groups  allow you to set local IPsec policy for
>  lists  of  remote  CIDRs  (names,  IPs  or  groups  of IPs), simply by
>  mentioning  the  CIDR  in  the  approriate  Policy  Group  file. Linux
>  FreeS/WAN  then  internally creates the connections needed to
>  implement that policy.

  This is an introductory paragraph, don't get into the minutia of
CDIRs and it'd details and the like, simply say something like ~by
listing hosts that you want to have special treatment in one of
several common~ bla bla bla

>  In the next section we describe our five Base Policy Groups, which you
>  can use to configure IPsec in many useful ways.

  This is called a teaser, it makes folks want to watch the next
episode of say Fuffy the Verboseness Slayer.  So mention here (oddly
adding fluff...) that the next section shows how to build a VPN out of
OE boxes with ONE line of config on each host or SG.

  Then for your NEXT trick you will...  Good luck.

		||ugh Daniel
		[email protected]

			Systems Testing & Project mis-Management
			The Linux FreeS/WAN Project
			http://www.freeswan.org

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3ia
Charset: noconv
Comment: For the matching public key, finger the Reply-To: address.

iQCVAwUBPlHndlZpdJR7FBQRAQG1jAP/YtXGR1EZTVWo/3w2T0ivlAx5ZQIjQJQR
4uw/ONzaHG+Tb0MMjK1PmLkRBOCp+LBya8QQImUQJSer2xeMwRdmbikR5SG4AkjM
AjW7WqNORGjcT7bor5Wr2MIDAl0/QF9oxNhiILK0v2qEFlALVPZ2ohJvQmtBTZ3t
XPIh6zar5+Q=
=jgSz
-----END PGP SIGNATURE-----