Re: Raw doc in the policy group files
Hugh Daniel <[email protected]> Mon, 17 Feb 2003 23:57:47 -0800
| Newsgroups | gmane.network.freeswan.devel |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Mz. Schmeing asked for some feedback on 2.00-notquiteyet doc, here it is: > Policy Groups are an elegant general mechanism to configure FreeS/WAN > IPsec. They are useful for about 95% of IPsec applications. I would say for ~'maybe' 95% of 'FreeSWAN' 'users'.~ or some such. > In the 1.x configuration model, in order to build IPsec connections > between pairs of nodes, you needed to configure a connection for each > pair. This made IPsec configuration an n-squared affair, and often > resulted in long, complex /etc/ipsec.conf files. I would say ~In previous FreeS/WAN~ and say something about having to do it at each end. Keep it short though, as we can't afford to bore folks, they might switch channels... I would trim the second sentacne down and just say it was a messy pain. > By contrast, Policy Groups allow you to set local IPsec policy for > lists of remote CIDRs (names, IPs or groups of IPs), simply by > mentioning the CIDR in the approriate Policy Group file. Linux > FreeS/WAN then internally creates the connections needed to > implement that policy. This is an introductory paragraph, don't get into the minutia of CDIRs and it'd details and the like, simply say something like ~by listing hosts that you want to have special treatment in one of several common~ bla bla bla > In the next section we describe our five Base Policy Groups, which you > can use to configure IPsec in many useful ways. This is called a teaser, it makes folks want to watch the next episode of say Fuffy the Verboseness Slayer. So mention here (oddly adding fluff...) that the next section shows how to build a VPN out of OE boxes with ONE line of config on each host or SG. Then for your NEXT trick you will... Good luck. ||ugh Daniel [email protected] Systems Testing & Project mis-Management The Linux FreeS/WAN Project http://www.freeswan.org -----BEGIN PGP SIGNATURE----- Version: 2.6.3ia Charset: noconv Comment: For the matching public key, finger the Reply-To: address. iQCVAwUBPlHndlZpdJR7FBQRAQG1jAP/YtXGR1EZTVWo/3w2T0ivlAx5ZQIjQJQR 4uw/ONzaHG+Tb0MMjK1PmLkRBOCp+LBya8QQImUQJSer2xeMwRdmbikR5SG4AkjM AjW7WqNORGjcT7bor5Wr2MIDAl0/QF9oxNhiILK0v2qEFlALVPZ2ohJvQmtBTZ3t XPIh6zar5+Q= =jgSz -----END PGP SIGNATURE-----