Re: IPSec in 2.5 Kernel?

Jim Carter <[email protected]> Thu, 20 Mar 2003 15:01:11 -0800 (PST)
Newsgroups gmane.network.freeswan.devel
Message-ID <[email protected]>
On Thu, 20 Mar 2003, John S. Denker wrote:
> On 03/20/2003 02:02 PM, Jim Carter wrote:
---snip---
> > "My module takes 4KB per connection" is more useful than
> > "your module won't scale".
>
> You mean like this?
> http://www.freeswan.org/freeswan_trees/freeswan-1.99/doc/performance.html

Apologies -- I had read this when installing FreeS/WAN, but forgot how much
useful stuff was in there, including your contribution about many tunnels
from a single gateway.  Are the KAME people reading this list, and if so,
do they have equivalent data that they could post a URL for?  I know
nothing about KAME.

>  > Or can we
>  > set it up similar to wireless networking, so (with the right tools,
>  > presetting the WEP key, etc.)
>
> We should strive to do muuuuuch better than that.
> Setting up WEP features is beyond the ability of
> most people who buy wireless equipment.

Maybe not beyond the ability -- the wireless products I've bought all had
setup guides that walk you through the procedure of setting up WEP (on
Windows) -- but a lot of purchasers don't think about the importance of
security.  And those who do set up WEP often don't think about AirSnort.
Which is why I've put a FreeS/WAN server on my net at work (both for
wireless and for home users), and why I am so bothersome about the issue of
clueless end users with NAT boxes who complain that they can't get ipsec to
work.

James F. Carter          Voice 310 825 2897    FAX 310 206 6673
UCLA-Mathnet;  6115 MSA; 405 Hilgard Ave.; Los Angeles, CA, USA  90095-1555
Email: [email protected]    http://www.math.ucla.edu/~jimc (q.v. for PGP key)