Re: IPSec in 2.5 Kernel?
Derek Atkins <[email protected]> 20 Mar 2003 02:39:48 -0500
| Newsgroups | gmane.network.freeswan.devel |
|---|---|
| Message-ID | <[email protected]> |
john,
> Where are the scalability and usability issues
> discussed?
You still have not defined what you mean by "scalabilty
and usability issues." Do you mean the number of simultaneous
IKE SAs? # of IPsec SAs? Packets per second? Mb/s?
> I don't understand why having an spdadd command
> distinct from the iptables command is a paragon of
> "integration".
in.te.grate \'int-*-.gra-t\ vb [L integratus, pp. of integrare, fr.
integr-, integer] 1: to form into a whole : UNITE 2a: to unite with
something else 2b: to incorporate into a larger unit 3: to find the
...
When I download the kernel from kernel.org, I want IPsec to be
a part of the download. *THAT* is integrated. If I have to
download the IPsec stack separately then I've already lost.
> > You cannot .... successfully route
> > packets after IPsec processing unless you want to
> > "route it to the next-hop".
>
> a) FreeS/WAN has issues with that, but most users
> won't notice.
It's bit me. It's bit Phil Karn. It's bit a number of
other people I know. I guess we don't count as "most
users", but it just doesn't work for relatively simple
(but non-standard) network architectures.
> b) The issues are fixable.
Maybe, but nobody has fixed them yet -- and the frees/wan people
wont accept _my_ fixes.
> Well, maybe I've got a giant blind spot, but I've
> been unable to find documentation how to use the
> KAME tools to build an automatically-keyed
> subnet-to-subnets VPN where N-1 of the gateways
> have dynamic wild-side addresses. This is something
> lots of customers want.
Could you please describe what you mean here? What do you
mean by "automatically-keyed subnet-to-subnets[sic] VPN"?
Can you point me at an architectural picture that described
this?
I _presume_ what you mean is that you've got a VPN gateway at
a central location and bunch of extruded subnets going to a
bunch of satellite offices? I also presume that the satellite
offices are "road warriors" with non-static IP addresses.
If automatic keying means OE, then no, it obviously cannot
use it. If "automatic keying" means "IKE with RSA without
pre-shared keys", then yes, it can do that (although only
with X.509 certs).
> I get 5 hits (none useful) from:
> http://www.google.com/search?q=raccoon+vpn+dhcp+documentation
>
> Even if it turns out to be easy for an expert to do,
> the lack of documentation is _ipso facto_ a usability
> issue.
>
> If making such a VPN easy to set up is a goal of
> the project, please let us know. That would be
> very reassuring.
If my presumption is correct above, and if you are NOT talking
about OE, then yes, this is a goal of the project. But really
the immediate goals are getting standards-compliant and feature
complete IPsec into the mainline Linux kernel and supporting
applications.
-derek
--
Derek Atkins
Computer and Internet Security Consultant
[email protected] www.ihtfp.com