Re: IPSec in 2.5 Kernel?

Derek Atkins <[email protected]> 20 Mar 2003 02:39:48 -0500
Newsgroups gmane.network.freeswan.devel
Message-ID <[email protected]>
john,

> Where are the scalability and usability issues
> discussed?

You still have not defined what you mean by "scalabilty
and usability issues."  Do you mean the number of simultaneous
IKE SAs?  # of IPsec SAs?  Packets per second?  Mb/s?

> I don't understand why having an spdadd command
> distinct from the iptables command is a paragon of
> "integration".

in.te.grate \'int-*-.gra-t\ vb [L integratus, pp. of integrare, fr. 
   integr-, integer] 1: to form into a whole : UNITE 2a: to unite with 
   something else 2b: to incorporate into a larger unit 3: to find the 
   ...

When I download the kernel from kernel.org, I want IPsec to be
a part of the download.  *THAT* is integrated.  If I have to
download the IPsec stack separately then I've already lost.

>  > You cannot .... successfully route
>  > packets after IPsec processing unless you want to
>  > "route it to the next-hop".
> 
> a) FreeS/WAN has issues with that, but most users
> won't notice.

It's bit me.  It's bit Phil Karn.  It's bit a number of
other people I know.  I guess we don't count as "most
users", but it just doesn't work for relatively simple
(but non-standard) network architectures.

> b) The issues are fixable.

Maybe, but nobody has fixed them yet -- and the frees/wan people
wont accept _my_ fixes.

> Well, maybe I've got a giant blind spot, but I've
> been unable to find documentation how to use the
> KAME tools to build an automatically-keyed
> subnet-to-subnets VPN where N-1 of the gateways
> have dynamic wild-side addresses.  This is something
> lots of customers want.

Could you please describe what you mean here?  What do you
mean by "automatically-keyed subnet-to-subnets[sic] VPN"?
Can you point me at an architectural picture that described
this?

I _presume_ what you mean is that you've got a VPN gateway at
a central location and bunch of extruded subnets going to a
bunch of satellite offices?  I also presume that the satellite
offices are "road warriors" with non-static IP addresses.

If automatic keying means OE, then no, it obviously cannot
use it.  If "automatic keying" means "IKE with RSA without 
pre-shared keys", then yes, it can do that (although only
with X.509 certs).

> I get 5 hits (none useful) from:
>    http://www.google.com/search?q=raccoon+vpn+dhcp+documentation
> 
> Even if it turns out to be easy for an expert to do,
> the lack of documentation is _ipso facto_ a usability
> issue.
> 
> If making such a VPN easy to set up is a goal of
> the project, please let us know.  That would be
> very reassuring.

If my presumption is correct above, and if you are NOT talking
about OE, then yes, this is a goal of the project.  But really
the immediate goals are getting standards-compliant and feature
complete IPsec into the mainline Linux kernel and supporting
applications.

-derek

-- 
       Derek Atkins
       Computer and Internet Security Consultant
       [email protected]             www.ihtfp.com