Re: IPSec in 2.5 Kernel?
Paul Wouters <[email protected]> Thu, 20 Mar 2003 23:53:43 +0100 (MET)
| Newsgroups | gmane.network.freeswan.devel |
|---|---|
| Message-ID | <[email protected]> |
On Thu, 20 Mar 2003, Jim Carter wrote:
> Not to express support for either side of the flame war, but I would be
> interested to see an analysis of what would happen if just about every
> net connection were encrypted by {old vs. new} KLIPS and managed by {pluto
> vs. racoon}.
> ad infinitum. On the other end, watch the big server setting up
> connections which the peers use for 10 packets and then allow to time out.
We were running OE on our main servers just before we added TLS to sendmail.
Our dns IP was the only ip not OE'ed. Minor webservers were OE'ed, but
our main webserver was given passive OE only. Also, our fallback MX has
no OE, so if things fail, the flow of mail will still continue.
We added this to our servers without telling anyone. We received one or two
complains about email, but couldn't pinpoint the blame to OE. In fact,
it is currently disabled (working on pre2 OE) and we 're still getting a
few problem reports. This seems mostly a general timeout issue, most
often with Postfix, and a filter in one case (filtering on the push flag??)
However, most of the connections were ofcourse non-OE. Servers would have
at most about a hundred pass routes, and upto five tunnels. Our only
problem was the huge increase in logfile size because of the logging of
failed OE connections. I believe with my contact with the team members, the
lists, and currently hosting www.freeswan.org (on passive OE) my network
is likely one of the more busier OE-wise.
The impact has been minimal, but frankly, OE needs to be put on some
major distribution before we can really judge the impact of OE on full
production servers. I hope this will happen soon, but I think it is still
a little while away.
Paul