|
From: Oliver J. <oli...@mo...> - 2004-03-02 13:22:38
|
i don't know, if it make's sense to make freeswan really running under 2.6 as i proposed in the past ??? http://www.freeswan.org/ending_letter.html think, resources can be burned otherwise... cheers oliver |
|
From: Bruce S. <bw...@ar...> - 2004-03-02 14:25:40
|
> i don't know, if it make's sense to make freeswan really running > under 2.6 as i proposed in the past ??? > > http://www.freeswan.org/ending_letter.html > > think, resources can be burned otherwise... Yes, it appears "the FreeS/WAN project will be coming to an end" (to quote their web page). According to slashdot, "KAME" was selected as the standard Linux IPSEC implementation. Does anyone have any experience with KAME? (I've never even heard of it myself) Maybe we should think about switching DL to include KAME instead of FreeS/WAN? - BS |
|
From: Oliver J. <oli...@mo...> - 2004-03-02 14:53:30
|
On Tue, 2004-03-02 at 15:12, Bruce Smith wrote: > According to slashdot, "KAME" was selected as the standard Linux IPSEC > implementation. Does anyone have any experience with KAME? (I've never > even heard of it myself) Maybe we should think about switching DL to > include KAME instead of FreeS/WAN? > KAME/racoon is already in the tree but working only witha a 2.6 kernel... there exists a backport of the ipsec-infrastructure for 2.4, if you look in the redhat kernels, but i never tried to patch a vanilla 2.4 i would rather suggest 2.4 = freeswan (until a maintained 2.6 ipsec backport is available) 2.6 = KAME/racoon i've only played with racoon, but its easy to configure and there exists a good how-to on the web for it. http://www.ipsec-howto.org/ |
|
From: Bruce S. <bw...@ar...> - 2004-03-02 15:15:34
|
> > According to slashdot, "KAME" was selected as the standard Linux IPSEC > > implementation. Does anyone have any experience with KAME? (I've never > > even heard of it myself) Maybe we should think about switching DL to > > include KAME instead of FreeS/WAN? > > KAME/racoon is already in the tree but working > only witha a 2.6 kernel... > > there exists a backport of the ipsec-infrastructure for 2.4, if you > look in the redhat kernels, but i never tried to patch a vanilla 2.4 > > i would rather suggest > > 2.4 = freeswan (until a maintained 2.6 ipsec backport is available) > 2.6 = KAME/racoon I guess it also depends if the next stable release will be 2.6 only, or a choice of 2.4/2.6. > i've only played with racoon, but its easy to configure and there exists > a good how-to on the web for it. > > http://www.ipsec-howto.org/ An IPSEC implementation that is easy to configure? Isn't that an oxymoron? ;-) - BS |
|
From: Friedrich L. <fl...@fl...> - 2004-03-02 21:14:38
|
Oliver Jehle wrote on 02.03.2004 15:40 MET: > > i would rather suggest > > 2.4 = freeswan (until a maintained 2.6 ipsec backport is available) I think FreeSwan will still have the lead in the 2.4 arena. Anything backported will probably not be as stable. -- MfG / Regards Friedrich Lobenstock ____________________________________________________________________ Friedrich Lobenstock Linux Services Lobenstock URL: http://www.lsl.at/ Email: fl...@fl... ____________________________________________________________________ |
|
From: Martin G. <sou...@gl...> - 2004-03-03 03:38:25
|
On March 2, 2004 14:01, Friedrich Lobenstock wrote: > Oliver Jehle wrote on 02.03.2004 15:40 MET: > > i would rather suggest > > > > 2.4 = freeswan (until a maintained 2.6 ipsec backport is available) > > I think FreeSwan will still have the lead in the 2.4 arena. Anything > backported will probably not be as stable. Don't write off FreeS/wan just quite yet - some of the developers have forked FreeS/wan into a new project - openswan and will continue their work there. One of the big advantages I found with FreeS/wan is the documentation and in particular the interoperability guides - they've helped me out in many cases. I'm unfamiliar with Kame, but in my brief reading it appears to be easier to configure, but is not as well tested as FreeS/wan. There may still be some issues with x509 certs and nat traversal, but I'm sure these will be solved in time... So, I would add my voice to the concensus and recommend DL sticks to FreeS/wan for kernel 2.4 and see where 2.6 goes. Martin |
|
From: Oliver J. <oli...@mo...> - 2004-03-03 06:30:19
|
> One of the big advantages I found with FreeS/wan is the documentation and in > particular the interoperability guides - they've helped me out in many cases. to make it clear, i'm not fixed on kame or freeswan.... i personally prefer a solution compatible with the kernel instead of patching the kernel. i read something about freeswan compatibility with 2.6 in version 2.06.. so if you have some free time :-) please contribute !!!!!!! a lot of freeswan users will be happy to migrate to 2.6 without changeing the vpn configuration. i will concentrate my work on kame/ipsec-tools, because it looks like the perfered solution for the kernel developers involved in this area. > I'm unfamiliar with Kame, but in my brief reading it appears to be easier to > configure, but is not as well tested as FreeS/wan. ask the bsd people for test results !! they use racoon long time... > There may still be some > issues with x509 certs and nat traversal, but I'm sure these will be solved > in time... > nat traversal is prepared for merge (in cvs).... x509 certs looks working for me... > So, I would add my voice to the concensus and recommend DL sticks to FreeS/wan > for kernel 2.4 and see where 2.6 goes. there should be no disussion if freeswan or kame is or should be the one and only solution... for 2.4 freeswan is the one and only maintained solution. so its the best solution... and 2.4 is in maintained mode, so its dead for new features now. (and backports). Oliver |